Live data from Hacker News

Why we won’t be supporting Sign in with Apple

blog.anylist.com

301–310 of 485 posts

Re: Why we won’t be supporting Sign in with Apple

#301

This seems to be a common problem, made more visible when using third-party authentication, that your application has taken the concepts of "Account" and "Authentication Method" as if they were the same thing. It appears that the "account ID", "preferred contact method+address" and "authentication ID" are all the same here - which then creates the "account management code into a rat’s nest" scenario they describe in…

I don’t see any technical reason this couldn’t be done, but it would be more work for both the app developers and the user.

Time and value are not "technical", though they can be measured.

Technically you can build an app that's purely a AR sticky notes specifically on your fridge... but the value of that app is approximately 0.

Re: Why we won’t be supporting Sign in with Apple

#302
post #277
post #228

Earlier quoted context omitted.

Obfuscation of the email address is an explicit choice by the user when using Sign in with Apple. It’s not something forced by the service. If users are choosing to do that, it says something about the lack of trust the users have with whatever they’re signing up for.

Not necessarily. I have an app with 1,000 users, and about 99% of them choose to obfuscate. My app isn’t untrustworthy at all either. It’s an experimental app which attempts to let users create an iOS app on iOS. My suspicion is that people choose to obfuscate because it’s what’s selected by default.

Most likely. Never underestimate the power of defaults

Re: Why we won’t be supporting Sign in with Apple

#303
post #218

Earlier quoted context omitted.

I think the problem is that once you want to be found, like for a grocery shopping app, most folks think you search and just find them and when it doesn't work....they don't know to go find some settings and figure it out.

Yeah but I dont want to be found. That's why I don't share my email. If I want to share with someone, I don't want the use that app to establish a link between us, because I don't want the app to know anything about us except what it must to do it's job. "Go find some setting and figure it out" is a UX fail. When I share eg a Dropbox link or a Google Photos link, you can get to it whether you have an established acco…

I get your use case.

But in this case the company is someone who claims to be "The best way to create and share a grocery shopping list and organize your recipes."

Sharing is part of the deal with them and a sign in process that from the start complicates it is understandably a no go / introduces all sorts of complications that they detail in the article.

Re: Why we won’t be supporting Sign in with Apple

#304

Worth noting that AnyList automatically subscribed me to a marketing list without double opt-in or any kind of consent, which is exactly the kind of behaviour that makes me not want apps to have my real email address.

They mention customer support so many times in that article, but it's a grocery list app! When is the last time I asked for support for the sticky note attached to my refrigerator? I don't doubt that there are indeed customers who need support from time to time, but surely it's a small minority. These seem to just be contrived arguments to protect their customer data selling bottom line.

Definitely picked up the same intentions from the post.

Seems out of place to complain about not having email addresses for "support" reasons.

If they truly cannot help users without asking for their email address, maybe they should not have users (login) then.

Re: Why we won’t be supporting Sign in with Apple

#305
post #5

Buries the lede. They’ve chosen to drop support for Facebook login rather than also support Apple login. So working as intended!

I'm going to be fascinated to see what this does for conversions. My company built the Neil Young Archives, when doing so we initially launched with Social log ins and at one point Neil decided Facebook and Google were evil and wanted to remove the access. According to our logs a full 2/3s of all users were registering with a social account and we were having great success getting folks to log into a free service (We…

I just gotta say I both love and hate the Neil Young archives. I hate them because the website is genuinely awful, and a chore to navigate around. However, I love that I have access to a load of stuff I haven't heard before.

At any rate, thanks for the hard work you put into it and I've used this site a lot.

Re: Why we won’t be supporting Sign in with Apple

#306

Earlier quoted context omitted.

Perhaps you don't use AnyList? It doesn't make sense to use with a private mail relay because they use email as an addressing system. And honestly, few users will go look up their per-app address and tell people to add them.

This is where their article lost credibility with me. Their decision to base their sharing and addressing system on email was their mistake, and Apple is just the first to force them to face their mistake. I don't want to share my spam email with all my friends to get them to share with me. And I don't want to give my primary email to an app that will spam me. If I want to share something, I'll send a link and the re…

It's not a mistake, by any means.

It's dead clear that you don't work with consumers. Your technical bias shows what you care about and you're(an me) are an utter minority.

If you want security, btw - you should have multiple passwords for different things. And ideally not even use a password manager.

Re: Why we won’t be supporting Sign in with Apple

#307

Earlier quoted context omitted.

Small nit: Potential hackers would only have access to your email, provider id and whatever other details they pass along (preferred name, profile picture URL, etc.). Social login doesn't provide consumers (AnyList in this case) with your password.

Agreed, social login like Facebook et. al do not provide passwords to consumers, but e-mail is already contentious enough. Most people use the same e-mail for every single account they have. A large majority of these users use the same password for all of their accounts. (Just want to clarify that I do neither of these things - I have a large set of e-mail aliases and have a unique & secure password for each account…

FYI: Getting a hold of someones' email isn't particularly hard.

Re: Why we won’t be supporting Sign in with Apple

#308

Earlier quoted context omitted.

How is this ironic? It is by design and obviously they know why people do it because the very next sentence says that. Why on Earth would you'd want to use a list-sharing app that uses email as the addressing system and then not share your email.

It's ironic because anylist cites that as a reason to stop supporting that very feature. That would only reduce my desire to Sign Up for that app.

As a reminder - us privacy aware technical people aren't remotely relevant anymore. So... You're not their target audience.

Re: Why we won’t be supporting Sign in with Apple

#309

> One problem is that most Apple IDs are tied to an iCloud email address. So most accounts created via Sign in with Apple will use an iCloud email address. But many of those iCloud email addresses are unused and unchecked, because a customer’s “real” email account is their Gmail, Yahoo, or Hotmail account. Wow, this is a really good point. I just checked and yup -- my AppleID is directly linked to my icloud email, an…

... I'm not sure I understand this scenario?

So you have an AppleID, which is a full iCloud account (i.e. not just an AppleID using a Gmail address.. So you login to iCloud on some device, and then specifically go untick the "Mail" option in iCloud preferences? Really?

Re: Why we won’t be supporting Sign in with Apple

#310

Earlier quoted context omitted.

I cope with this confusion by avoiding third-party login whenever possible. Why volunteer additional information about myself to Google or Facebook?

Because you can frequently avoid account creation, setting a new password etc if you click “sign in with google.” It’s a tradeoff but if you don’t see any value in it you maybe haven’t used it- it’s convenient.

I've had services ask me to create a username and password after I "log in with Google". I usually give up at that point.
Post reply on HN