Live data from Hacker News

Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

marco.org

101–110 of 110 posts

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#101
post #33
post #15

Hey everybody, Pierre from @sunrise. This is the blog post we've just published to give more context: "Users sometimes ask us why we require the user’s Apple ID and password in Sunrise, instead of using the local Calendar API. That’s a great question to ask, and we understand why users don’t want to share their credentials without context. We’ve thought a lot about that. The two reasons why we are doing this are: - o…

Why don't you run your own caldav server instead of relying upon icloud?

People want access to their apple calendar, on all their devices.

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#102

Admittedly, Android does it much better by providing oAuth, an easy way to get the users sign in, and of course APIs for almost all the popular features. And also, for installing $0 apps you don't need any credit card details at all. Even the buttons are different "Install" v/s "Buy".

You can set up an iTunes account without a credit card quite easily too: http://support.apple.com/kb/ht2534

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#103
post #82
post #79

Earlier quoted context omitted.

If you delete the app, this won't remove the account from sunrise's system then?

There is no way for app developers to know which users have deleted the app from their device.

Not exactly true. If you send a push notification to a device using a token of an app that isn't installed anymore, the feedback service will let you know that the app isn't installed on the device anymore[0].

[0] https://developer.apple.com/library/ios/documentation/Networ...

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#104
post #23
post #8

Earlier quoted context omitted.

You don't need to at all. I use two separate Apple IDs on my iOS devices. Apple ID accounts are individually configurable for most, if not all iCloud/App Store services.

To quote JWZ: "You have invoked the "Oh, but there's a preference to turn off that stupid behavior" defense. I am showering you with negativity." (Yes, it's not a preference pedantically, it's an option to create multiple accounts. Still the default and most used is using one account).

It's not even default behavior to use the same account. You are required to make an explicit decision during setup whether or not you want to use the same Apple ID for iCloud and the App Store.

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#105

Earlier quoted context omitted.

> Just never thought about it, because why would I? Anyone with family members using their iTunes account would and has for many years. That's why it's there.

It's there so that you can create a junk account for apps which want access to your credentials? Doubtful. Remember the context of the topic.

This thread started with:

"It's pretty crazy that you need to use the same credentials to "buy" a $0 app as you have to remotely lock and wipe your iphone and mac."

I'm having no trouble remembering the context. Why are you?

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#106
post #103
post #82

Earlier quoted context omitted.

There is no way for app developers to know which users have deleted the app from their device.

Not exactly true. If you send a push notification to a device using a token of an app that isn't installed anymore, the feedback service will let you know that the app isn't installed on the device anymore[0]. [0] https://developer.apple.com/library/ios/documentation/Networ...

What about users who didn't allow location services to begin with?

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#107
post #15

Hey everybody, Pierre from @sunrise. This is the blog post we've just published to give more context: "Users sometimes ask us why we require the user’s Apple ID and password in Sunrise, instead of using the local Calendar API. That’s a great question to ask, and we understand why users don’t want to share their credentials without context. We’ve thought a lot about that. The two reasons why we are doing this are: - o…

They should have rejected your app until they had an Oauth solution in place. That's the right answer to avoid training Apple users to be fishing targets. Sunrise doesn't have a (known) security problem. Sunrise happened to reveal a glaring problem with Apple's security policies.

How would OAuth help? The problem is training users that it's okay to enter their username and password into any schmuck's app... which is exactly what they'd be doing with OAuth. OAuth and its ilk are neat ways for honest app developers to avoid touching user credentials, and therefore (presumably) would have been a better solution for Sunrise, but they offer no protection against phishing in a native app.

Of course, OS X Authorization Services prompts for keychain access with a standard dialog that just pinky-swears it comes with the OS's blessing, so maybe Apple's approval of this practice shouldn't come as such a surprise.

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#108
post #55

Earlier quoted context omitted.

>> Admittedly, Android does it much better by providing oAuth, an easy way to get the users sign in, and of course APIs for almost all the popular features. First of all this has nothing to do with iOS/Android. This is an app trying to access a web service. Apple needs to provide oath or similar for accessing their iCloud services. >> And also, for installing $0 apps you don't need any credit card details at all. Eve…

You've always been able to use Google Play for free apps without a credit card...

Not true. What probably happened was that your Google Play account was tied to your mobile (i.e. Verizon) account, so charges made in Google Play was pushed to Verizon, who then pushed those charges to you. T-Mobile used to do that, and I needed no credit card, until about two years ago, when one was needed because T-Mobile or Google no longer wanted to do business that way.

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#109
post #34
post #32

Okay, I have a question. AppleID and pw non-withstanding, I have experienced the following. I played Where's my water2 recently and came to the end where you have to pay to get additional levels. No biggie, I did this with the first game as well. But, when I clicked the in app purchase and entered my password I was prompted with a pop saying I needed to answer my 3 security questions next. Of course I hit cancel and…

It seems Apple is keen to push the 3 security question setup after a while on app store interactions, it's probably just unfortunate that it appeared during an in-app purchase interaction.

I know this is older but just in case some one experienced the same thing, the above mentioned is true.

I experienced this on iTunes on my PC quite a while ago. And since then I have not made any purchases from the iOS device itself. I buy through the PC and then sync to my devices because of slow internet.

So now, basically when I tried to make an IAP, I got the same popup. I first thought it was the app that wanted to know my details but it really is Apple. I got this out of the way by purchasing a small, 99ct app directly from my Device. So I went into the AppStore, bought the app and the same popup came up. Since this was now in the official Apple Appstore app, I answered two of my questions, downloaded the app and now, this popup is gone and I can make IAP all I like.

Re: Apparently It’s OK For iOS Apps To Ask For Your Apple ID And Password

#110
post #13

Earlier quoted context omitted.

IAP is required for virtual goods used within the app. It's fine to ask for a credit card number to purchase physical goods and services. That's why Apple hasn't shut down Uber and Square.

I am guessing you can trust the app with ur credit Card because of AppStore's rigorous entry tests?

What point are you even trying to make? You trust the app for the same reasons you trust a web site you put your credit card number into, or the card reader that the cashier uses at the local business down the street.
Post reply on HN