Live data from Hacker News

Face ID and Touch ID for the Web

webkit.org

161–170 of 371 posts

Re: Face ID and Touch ID for the Web

#162
I am not comfortable with Apple getting any control over the web. Thankfully, so far the web is mostly free from Apple's clutches and they can run their fiefdom only in the App universe.

I shudder to think of a future where websites will have to implement some version of Apple's In-App Purchases program and give 30% of the revenue to Apple or else they won't be allowed to render on Apple devices.

Re: Face ID and Touch ID for the Web

#163
post #71
post #50

Earlier quoted context omitted.

> I would definitely stay away from any "Sign in with Apple". I would stay away from any "Sign in with.." service as a user and as a product owner. You're affectively giving away a major control of your users to a third party.

As a product owner, why wouldn't I want to piggyback on the millions of dollars of R&D + security that the big companies have put in? And as a user, why would I trust my password to the website that rolled their own authentication over the big companies?

> why would I trust my password

Other people have mentioned this, but if you're not reusing passwords, this shouldn't be a concern for you. Don't reuse passwords!

On the security front, companies that are implementing 3rd-party sign-in can still get hacked and leak your personal information. If that information is supplied by Apple instead of you, it's all the same. You don't automatically get better security because you're using 3rd-party sign-in, you only get better security if you're being forced to stop doing something bad (reusing passwords, enabling 2FA) or if Apple is providing less information than an account would ask for during signup.

To Apple's credit on that front, they do mask your email, which is a legitimate privacy improvement. But it would be better for that to be a generic service that allowed you to generate an anonymous email at any time for anything, rather than a perk that's hardwired into an anti-competitive scheme to make it harder for you to migrate devices or change services.

Re: Face ID and Touch ID for the Web

#164
post #71

Earlier quoted context omitted.

As a product owner, why wouldn't I want to piggyback on the millions of dollars of R&D + security that the big companies have put in? And as a user, why would I trust my password to the website that rolled their own authentication over the big companies?

> why would I trust my password... Do you use the same password everywhere, by any chance? :)

I used to, but some websites stopped accepting "abc123"!

Thankfully, it's still fine for my bank login.

Re: Face ID and Touch ID for the Web

#166

Earlier quoted context omitted.

Wow, you can’t even use sign in with Apple if you “Show Apple or its products in a false or derogatory light.” Who decides what’s false or derogatory?

A court of law.

No, there's no world where Apple blocks access to an account because they're showing derogatory content towards Apple products, and a company gets a judge to overturn that block because it's not technically libel. Apple has the right to block you from their sign-in for any reason. Short of pulling a move like Epic and suing them for antitrust, a court of law is never going to enter into the equation.

None of these are legal definitions, Apple gets to decide what they mean. And no court of law is going to rule that they don't have the right to block when their TOS end with:

> Apple reserves the right to disable Sign in with Apple on a website or app for any reason at any time.

Re: Face ID and Touch ID for the Web

#167

Earlier quoted context omitted.

A court of law.

No, there's no world where Apple blocks access to an account because they're showing derogatory content towards Apple products, and a company gets a judge to overturn that block because it's not technically libel. Apple has the right to block you from their sign-in for any reason. Short of pulling a move like Epic and suing them for antitrust, a court of law is never going to enter into the equation. None of these ar…

> Apple gets to decide what they mean.

(IAAL, this is not legal advice.)

That's not how contract law works. There's a whole body of law around how to construe language in contracts, and it's subject to litigation and dispute if the definition isn't made clear in the contract itself.

> no court of law is going to rule that they don't have the right to block

Then you don't know courts very well. Such clauses are still subject to the law and public policy. For example, no competent court is going to allow anyone to use an escape clause to terminate a contract with someone because of their race, age, or gender.

But yeah, if you use someone's services and then publicly talk trash about them? Why should they be forced to continue to do business with you?

Re: Face ID and Touch ID for the Web

#168
post #137

Earlier quoted context omitted.

As a user I would prefer no account in most cases. As a distant second, I would prefer the convenience, security, and privacy of Sign in with Apple over Google, Facebook, or the headache of managing yet another web account . As a developer, I use my preferences as a user to steer my choices, but recognize that the world doesn't revolve around Apple so would allow other options. > Having saw Epic's developer account t…

> Since I have zero need to deliberately violate Apple's App Story policy, I don't worry about this overmuch. That may be true today, but their policies are a moving target. Who knows what they'll be like in a year's time?

> That may be true today, but their policies are a moving target. Who knows what they'll be like in a year's time?

Likewise Google, Facebook, or any site/ API that a developer deals with on a daily basis.

I wouldn’t bet my company on any sign in with _____ service. I just feel the trade-offs with Apple’s sign in versus Google/ Facebook to be less bad. With any of the services, I might do something that causes me issues down the road. With Apple at least I’m not selling out my users immediately.

Re: Face ID and Touch ID for the Web

#169
post #33
post #13

So happy Apple decided to go with an open standard here rather than something proprietary. This is good news for the FIDO2 ecosystem and I hope this leads to far greater support for FIDO2 authenticators of all types. There is another world in which Apple just pushed 'Sign in with Apple' and created yet another federated identity provider rather than true, 'secure element'-based FIDO2 authentication.

"Sign in with Apple" requires a developer account with Apple. Having saw Epic's developer account terminated by Apple, I would definitely stay away from any "Sign in with Apple". (FWIW, the only 2fa with "Sign in with Apple", if you don't own any Apple hardware, is SMS.)

It's pretty clear Epic set out to intentionally get their Apple developer account terminated so they would have standing to sue, so I would not draw too much inference from that.

That said, it's generally true that any dependence on a platform is a form of risk. There are documented examples of Google kicking people out of their ecosystem unexpectedly too.

Federated sign-in schemes may be a good idea if they help your users create accounts and authenticate more easily, but it certainly seems smart to offer more than one, including your own email-based option.

Re: Face ID and Touch ID for the Web

#170
post #136

Earlier quoted context omitted.

As a user I would prefer no account in most cases. As a distant second, I would prefer the convenience, security, and privacy of Sign in with Apple over Google, Facebook, or the headache of managing yet another web account . As a developer, I use my preferences as a user to steer my choices, but recognize that the world doesn't revolve around Apple so would allow other options. > Having saw Epic's developer account t…

I've had an issue with sign-in with Apple where using an autogenerated emails ruins certain support interactions. One of them was cancelling a subscription service that was eventually resolved (they required me to email their customer support, which I couldn't figure out how to do using the autogenerated email address created by "sign-in with Apple").

While it’s frustrating and worth pointing out of course - what really happened there was a bug in the service provider’s support process!
Post reply on HN