4 ms·
A 99 USD commercial web API. This one, and their other endpoints, require being part of paid Apple Developer program. I understand, but it's frustrating if you'
by jamsinclair 7y ago
A 99 USD commercial web API. This one, and their other endpoints, require being part of paid Apple Developer program. I understand, but it's frustrating if you're wanting to play around or use in free open source.
- saagarjha 7y agoDo any competing platforms have a similar API with a less imposing barrier?
- mixedCase 7y agoSpotify and Deezer, OTOH.
- cptskippy 7y agoI'm ok with it. It deincentivizes abuse not unlike how SSL originally worked before it became a farming operation.
- devwastaken 7y agoI'm curious how SSL is being abused.
- cptskippy 7y agoOnce upon a time businesses had to submit paper work verifying their business to a registrar to get an SSL cert. It wasn't just about encryption but also identity. I remember as late as 2004 trying to scrounge up copies of our business license to fax or mail into our registrar. Today the SSL cert has lost it's identity aspect and is just a sign of secure communication, not trusted.
- nine_k 7y agoExtended validation certificates still exist, and do require the paperwork.
- tonyedgecombe 7y agoAs do code signing certs (for Windows developers).
- cptskippy 7y agoYes and no one really gives a crap about them anymore.
- duskwuff 7y ago> Once upon a time businesses had to submit paper work verifying their business to a registrar to get an SSL cert. It wasn't just about encryption but also identity. And those policies made it impossible for personal and hobbyist sites to use secure communications, while doing very little to actually prevent abuse. (Most of the apparent "success" of these policies was simply because the motivations for abuse were lower at the time.)
- devwastaken 7y agoSSL was never a sign of trust. That's what people made up. The algorithm has no intention of 'trust'. Ease of SSL certs provides significantly better protection from threats between you and legitimate sites than potential illigitimate sites.
- cptskippy 7y agoOriginally SSL required identity verification and financial costs were very high. Fraudulent SSL certs weren't a thing because the barrier to entry way so high and the rewards for spoofing a site were low since e-commerce was insignificant.
- rochak 7y agoThis is also the reason why I couldn’t contribute to an open source project that required being part of Apple Developer Program.