Earlier quoted context omitted.
> Why do you want my email address Because Apple's SSO will not be eternal and nobody wants to have a tier as a proxy on an important account credential. Apple SSO is ok for throwaway account where your account has no "sentimental value" that you can't recreate easily. But the author of this post maintains a social network : nobody wants to be locked out a social network. I have active accounts on websites that exist…
Don't forget in your threat model that Apple can cancel your account at any time for any reason whatsoever. They've even done it to security researchers using Apple's own bug bounty program. If that happens, you are stranded with those accounts effectively inaccessible to you forever. https://appleinsider.com/articles/21/04/20/man-sues-apple-fo...
My small revenge on Apple
171–180 of 471 posts
Re: My small revenge on Apple
#172Earlier quoted context omitted.
You’ve got to be kidding. Don’t use apple SSO because apple might not exist one day? You may as well argue not signup to anything using gmail because, heck, google might go out of business. There is no benefit to users in giving your “real” details to service providers; the benefit is entirely on their side. You can argue that Apple is harming the opportunities for 3rd party developers, sure, taking advantage of them…
Apple is not going anywhere, but they can terminate your account on a whim: https://appleinsider.com/articles/21/04/20/man-sues-apple-fo... So has Google, and presumably the other platforms as well.
Re: My small revenge on Apple
#173Earlier quoted context omitted.
You’ve got to be kidding. Don’t use apple SSO because apple might not exist one day? You may as well argue not signup to anything using gmail because, heck, google might go out of business. There is no benefit to users in giving your “real” details to service providers; the benefit is entirely on their side. You can argue that Apple is harming the opportunities for 3rd party developers, sure, taking advantage of them…
> You may as well argue not signup to anything using gmail because, heck, google might go out of business. I personally avoid to do it, but that's not the point. Every other third party allows account recovery by mail : if you want to stop using FB or Google's SSO, you can ask the website to send you a mail to prove the account ownership. If Apple's SSO stopped working (because Apple stopped it, banned you, because y…
They have SMS as a fallback. I know it's insecure and I'd rather they support TOTP, but let's not pretend having an Apple device is the only way to receive 2FA codes for your Apple ID.
Re: My small revenge on Apple
#174Earlier quoted context omitted.
If you have an Apple ID, you’re already implicitly trusting Apple to use that data appropriately. Apple doesn’t sell its user data. So anybody who is using Sign In with Apple trusts Apple to do the right thing. Besides, what monopoly? Apple is perfectly happy with other single sign ons — provided you also offer Sign In With Apple.
If Apple is perfectly happy with other sign on, then privacy is certainly off the table. Otherwise, they wouldn't allow apps in their store offering any other sign on (extreme analogy would be apps with virus in it). Then why force developers to add Apple sign on even they don't want to, instead of just encouraging? They can easily do so by telling developers that "apps with no Apple sign on are allowed, but are plac…
If the only other options you provide are Google or Facebook, you (as an app developer) clearly doesn’t care that much about privacy.
Apparently Apple doesn’t feel that any other providers care enough. That’s why they’re mandating the use of their privacy-focused solution.
Re: My small revenge on Apple
#175Anyone who puts privacy in quotes has totally lost the plot. Is it really so inconceivable to some two-bit developer that I absolutely do trust Apple more than I trust them? Hell, I trust Apple more than I trust Facebook and Google. Apple ID is my go to SSO these days. Is Apple perfect? No. But this is a game of lesser of evils.
You don't need to choose between Apple, FB, or Google. You can sign up with your email address, which means these companies get no analytics on your behavior
The reason "privacy" is in quotes is that some of us have started seeing through what Apple really means every time they use the word. As the EU's Executive Vice-President Margrethe Vestager has recently said regarding their Apple probe, privacy can't be an excuse to stifle competition.
https://appleinsider.com/articles/21/07/02/eu-antitrust-head...
Re: My small revenge on Apple
#176Earlier quoted context omitted.
They implemented end to end encryption in iMessage to collect more data? There's a vast array of technical instances where apple has gone above and beyond to implement privacy preserving technology, even when they weren't talking about it. This is, like the OP, hysteria without any basis in fact.
>They implemented end to end encryption in iMessage to collect more data? iMessage backed up on iCloud where Apple has key to decrypt.
Re: My small revenge on Apple
#177So the creator/developer of "The King of Organigrams and Family Trees" (that's the title of the app's website ( https://www.groupsapp.online )) is complaining that Apple is giving its users the ability to hide their email information, am I right? So isn't this a good thing? For me, it is. I don't want to give away my actual email address. I get too much spam already. So I thank Apple for this feature. And of course,…
The author seems a little in need of therapy and to walk away from this for a little while with just how angry, sarcastic, and tonedeaf it all reads and to be clear, I'm in therapy, it's great and helps.
Honestly, I don't know why he is offering social login on an app that advertises E2E chat anyways, you are just giving them all the Keys to the Kingdom.
Re: My small revenge on Apple
#178Earlier quoted context omitted.
Don't forget in your threat model that Apple can cancel your account at any time for any reason whatsoever. They've even done it to security researchers using Apple's own bug bounty program. If that happens, you are stranded with those accounts effectively inaccessible to you forever. https://appleinsider.com/articles/21/04/20/man-sues-apple-fo...
So? Google can also cancel your account at any time for any reason whatsoever, and good luck getting it back unless you're a celebrity with connections or manage to make a big enough fuss about it on social media. Using the same logic, you should not use Gmail then.
Re: My small revenge on Apple
#179Earlier quoted context omitted.
> You may as well argue not signup to anything using gmail because, heck, google might go out of business. I personally avoid to do it, but that's not the point. Every other third party allows account recovery by mail : if you want to stop using FB or Google's SSO, you can ask the website to send you a mail to prove the account ownership. If Apple's SSO stopped working (because Apple stopped it, banned you, because y…
> because you dont have Apple devices anymore so you are locked out of their proprietary 2FA They have SMS as a fallback. I know it's insecure and I'd rather they support TOTP, but let's not pretend having an Apple device is the only way to receive 2FA codes for your Apple ID.
I pretend nothing, I just didn't knew it since I had an iPhone for years.
Re: My small revenge on Apple
#180Earlier quoted context omitted.
No one is forcing users to use Google or FB. They can do traditional email signup
That is definitely not true for every app. There was never any clause in the App Store guidelines that you must provide traditional email signup. At least this way, the social-only apps will be forced to provide you a more privacy-preserving alternative, and for ones that don't use social logins anyway, nothing changes.
Which used to offer both social sign-up (FB and Google) and a traditional email sign-up option
You probably don't know that in this case, Groups was also forced to include AppleID or risk being removed from the App Store
Removing all social logins from this point to ensure compliance would have definitely affected all users who had originally signed in with FB/Google, way before AppleID ever existed