Live data from Hacker News

My small revenge on Apple

javierantonsblog.blogspot.com

171–180 of 471 posts

Re: My small revenge on Apple

#171
post #162
post #42

Earlier quoted context omitted.

> Why do you want my email address Because Apple's SSO will not be eternal and nobody wants to have a tier as a proxy on an important account credential. Apple SSO is ok for throwaway account where your account has no "sentimental value" that you can't recreate easily. But the author of this post maintains a social network : nobody wants to be locked out a social network. I have active accounts on websites that exist…

Don't forget in your threat model that Apple can cancel your account at any time for any reason whatsoever. They've even done it to security researchers using Apple's own bug bounty program. If that happens, you are stranded with those accounts effectively inaccessible to you forever. https://appleinsider.com/articles/21/04/20/man-sues-apple-fo...

So? Google can also cancel your account at any time for any reason whatsoever, and good luck getting it back unless you're a celebrity with connections or manage to make a big enough fuss about it on social media. Using the same logic, you should not use Gmail then.

Re: My small revenge on Apple

#172
post #163

Earlier quoted context omitted.

You’ve got to be kidding. Don’t use apple SSO because apple might not exist one day? You may as well argue not signup to anything using gmail because, heck, google might go out of business. There is no benefit to users in giving your “real” details to service providers; the benefit is entirely on their side. You can argue that Apple is harming the opportunities for 3rd party developers, sure, taking advantage of them…

Apple is not going anywhere, but they can terminate your account on a whim: https://appleinsider.com/articles/21/04/20/man-sues-apple-fo... So has Google, and presumably the other platforms as well.

Exactly, the same thing can happen with Google, so are you suggesting that users should not use direct email signup with Gmail either?

Re: My small revenge on Apple

#173
post #103

Earlier quoted context omitted.

You’ve got to be kidding. Don’t use apple SSO because apple might not exist one day? You may as well argue not signup to anything using gmail because, heck, google might go out of business. There is no benefit to users in giving your “real” details to service providers; the benefit is entirely on their side. You can argue that Apple is harming the opportunities for 3rd party developers, sure, taking advantage of them…

> You may as well argue not signup to anything using gmail because, heck, google might go out of business. I personally avoid to do it, but that's not the point. Every other third party allows account recovery by mail : if you want to stop using FB or Google's SSO, you can ask the website to send you a mail to prove the account ownership. If Apple's SSO stopped working (because Apple stopped it, banned you, because y…

> because you dont have Apple devices anymore so you are locked out of their proprietary 2FA

They have SMS as a fallback. I know it's insecure and I'd rather they support TOTP, but let's not pretend having an Apple device is the only way to receive 2FA codes for your Apple ID.

Re: My small revenge on Apple

#174

Earlier quoted context omitted.

If you have an Apple ID, you’re already implicitly trusting Apple to use that data appropriately. Apple doesn’t sell its user data. So anybody who is using Sign In with Apple trusts Apple to do the right thing. Besides, what monopoly? Apple is perfectly happy with other single sign ons — provided you also offer Sign In With Apple.

If Apple is perfectly happy with other sign on, then privacy is certainly off the table. Otherwise, they wouldn't allow apps in their store offering any other sign on (extreme analogy would be apps with virus in it). Then why force developers to add Apple sign on even they don't want to, instead of just encouraging? They can easily do so by telling developers that "apps with no Apple sign on are allowed, but are plac…

No, you got it the wrong way around. This puts privacy on the table. This way, I can choose to use Sign In with Apple.

If the only other options you provide are Google or Facebook, you (as an app developer) clearly doesn’t care that much about privacy.

Apparently Apple doesn’t feel that any other providers care enough. That’s why they’re mandating the use of their privacy-focused solution.

Re: My small revenge on Apple

#175

Anyone who puts privacy in quotes has totally lost the plot. Is it really so inconceivable to some two-bit developer that I absolutely do trust Apple more than I trust them? Hell, I trust Apple more than I trust Facebook and Google. Apple ID is my go to SSO these days. Is Apple perfect? No. But this is a game of lesser of evils.

Hi, here the 2-bit dev

You don't need to choose between Apple, FB, or Google. You can sign up with your email address, which means these companies get no analytics on your behavior

The reason "privacy" is in quotes is that some of us have started seeing through what Apple really means every time they use the word. As the EU's Executive Vice-President Margrethe Vestager has recently said regarding their Apple probe, privacy can't be an excuse to stifle competition.

https://appleinsider.com/articles/21/07/02/eu-antitrust-head...

Re: My small revenge on Apple

#176
post #157

Earlier quoted context omitted.

They implemented end to end encryption in iMessage to collect more data? There's a vast array of technical instances where apple has gone above and beyond to implement privacy preserving technology, even when they weren't talking about it. This is, like the OP, hysteria without any basis in fact.

>They implemented end to end encryption in iMessage to collect more data? iMessage backed up on iCloud where Apple has key to decrypt.

Well, kind of. Apparently Messages in iCloud is still E2E encrypted, but not if you have full-device iCloud Backup enabled. Though I've often been prompted for my previous passcode to restore data from an iCloud backup, so not sure if anything has changed on that front.

Re: My small revenge on Apple

#177

So the creator/developer of "The King of Organigrams and Family Trees" (that's the title of the app's website ( https://www.groupsapp.online )) is complaining that Apple is giving its users the ability to hide their email information, am I right? So isn't this a good thing? For me, it is. I don't want to give away my actual email address. I get too much spam already. So I thank Apple for this feature. And of course,…

The guy complains about those login buttons but the app is very much possibly the worst design I may have ever seen when I looked on his site. It harkens back to bad knockoff Metro UI text designs where the designer failed to read any form of typographic guidelines.

The author seems a little in need of therapy and to walk away from this for a little while with just how angry, sarcastic, and tonedeaf it all reads and to be clear, I'm in therapy, it's great and helps.

Honestly, I don't know why he is offering social login on an app that advertises E2E chat anyways, you are just giving them all the Keys to the Kingdom.

Re: My small revenge on Apple

#178
post #162

Earlier quoted context omitted.

Don't forget in your threat model that Apple can cancel your account at any time for any reason whatsoever. They've even done it to security researchers using Apple's own bug bounty program. If that happens, you are stranded with those accounts effectively inaccessible to you forever. https://appleinsider.com/articles/21/04/20/man-sues-apple-fo...

So? Google can also cancel your account at any time for any reason whatsoever, and good luck getting it back unless you're a celebrity with connections or manage to make a big enough fuss about it on social media. Using the same logic, you should not use Gmail then.

Exactly, you should not use Gmail then. But that's off-topic.

Re: My small revenge on Apple

#179
post #103

Earlier quoted context omitted.

> You may as well argue not signup to anything using gmail because, heck, google might go out of business. I personally avoid to do it, but that's not the point. Every other third party allows account recovery by mail : if you want to stop using FB or Google's SSO, you can ask the website to send you a mail to prove the account ownership. If Apple's SSO stopped working (because Apple stopped it, banned you, because y…

> because you dont have Apple devices anymore so you are locked out of their proprietary 2FA They have SMS as a fallback. I know it's insecure and I'd rather they support TOTP, but let's not pretend having an Apple device is the only way to receive 2FA codes for your Apple ID.

> let's not pretend

I pretend nothing, I just didn't knew it since I had an iPhone for years.

Re: My small revenge on Apple

#180

Earlier quoted context omitted.

No one is forcing users to use Google or FB. They can do traditional email signup

That is definitely not true for every app. There was never any clause in the App Store guidelines that you must provide traditional email signup. At least this way, the social-only apps will be forced to provide you a more privacy-preserving alternative, and for ones that don't use social logins anyway, nothing changes.

Of course, my comment was related to the app of the post Groups specifically

Which used to offer both social sign-up (FB and Google) and a traditional email sign-up option

You probably don't know that in this case, Groups was also forced to include AppleID or risk being removed from the App Store

Removing all social logins from this point to ensure compliance would have definitely affected all users who had originally signed in with FB/Google, way before AppleID ever existed

Post reply on HN