12 ms·
Seems a bit petty to me. As a developer I empathize with the possible lack of documentation (I don’t know, I never tried to integrate Sign In with Apple) but as
by spinningarrow 5y ago
Seems a bit petty to me. As a developer I empathize with the possible lack of documentation (I don’t know, I never tried to integrate Sign In with Apple) but as a user I actually am super happy with it. Nowadays any iOS app that doesn’t support logging in with Apple makes me think twice about whether I really need the app.
- dkdbejwi383 5y ago> Nowadays any iOS app that doesn’t support logging in with Apple makes me think twice about whether I really need the app. I agree. I only create accounts for things reluctantly. Because 1. Why do you want my email address, or DOB, or whatever else? I don't want your marketing, and 2. I can't be bothered, I downloaded your app because I have something I want to get done.
- pjerem 5y ago> Why do you want my email address Because Apple's SSO will not be eternal and nobody wants to have a tier as a proxy on an important account credential. Apple SSO is ok for throwaway account where your account has no "sentimental value" that you can't recreate easily. But the author of this post maintains a social network : nobody wants to be locked out a social network. I have active accounts on websites that existed back when Apple was fighting not to die and I would have totally lost access to them if I had to sign-in to them through my Lycos account.
- wokwokwok 5y agoYou’ve got to be kidding. Don’t use apple SSO because apple might not exist one day? You may as well argue not signup to anything using gmail because, heck, google might go out of business. There is no benefit to users in giving your “real” details to service providers; the benefit is entirely on their side. You can argue that Apple is harming the opportunities for 3rd party developers, sure, taking advantage of them? Sure. …but let’s not try to frame this as somehow “pro consumer” to give your email away so people can spam you with notifications and offers to lift their engagement rates. That is pure BS.
- simion314 5y ago>Don’t use apple SSO because apple might not exist one day? >You may as well argue not signup to anything using gmail because, heck, google might go out of business. I assume OP point is that Apple or Google could still exists but your accounts might not exist, maybe you get banned or just decide you don't want to use Apple/Google/FB anymore.
- ascar 5y agoI don't think your tone is warranted and in the spirit of this community. I don't agree with GP's fear of Apple SSO vanishing without a transition period to something else, but the general premise that this form of login is not eternal but rather short lived in the grand scheme of things is reasonable and doesn't warrant your aggressiveness. Also you might get locked out of your Apple account for a number of reasons and will then lose access to much more than just Apple services.
- imwillofficial 5y agoAnd this is a risk for the user to take on, night a choice that should be left to a petty developer.
- user-the-name 5y agoIt is also not really a valid argument here, given that the service we are talking about was offering Facebook and Google login options, which share the exact same issue, but with the added privacy violations of those platforms.
- j2bax 5y agoFacebook and Google login were options in addition to standard email sign up.
- user-the-name 5y agoAnd Sign in with Apple is another option in addition to those.
- martimarkov 5y agoSign In with Apple allows you to share your email so you are incorrect. If I decide to hide my email and be locked out - my choice. Developers and companies are greedy for data. Why do we have the expectation that emails should be shared? I constantly say don’t send me marketing and some services send. On my part I report them as spam every time so that algos start blocking them as they are breaking our contract and are malicious. For every service I’ve built allow the user to create an account with email, Google, Microsoft, Apple, Twitter, Facebook and to later untie their account and move to email. Also if they ever get locked out from their oauth account they can use the email to create a password and login via the normal way.
- pjerem 5y ago> Also if they ever get locked out from their oauth account they can use the email to create a password and login via the normal way. This is exactly my point ! You can't recover your account if you don't know the mail used for registration. Even if you remembered it, no check could be made if Apple stopped to proxy the mails for one or another reason. With other providers, you could always recover an account because your email address would let you prove the ownership of the account.
- gowld 5y agoWhat if my email address stops getting mail for one or another reason?
- dkdbejwi383 5y agoThen it loses marketing value and data hungry companies no longer care
- Redoubts 5y agoThe point is Apple relay goes under is the same risk as gmail goes under.
- Nextgrid 5y agoApple's SSO may not be eternal but it's also very unlikely to disappear overnight. If it is indeed going to be phased out you will have advance notice of this and a transition period. I agree that in a perfect world you'd provide your real email address and solve this problem. But developers and companies have repeatedly proven themselves to not be trustworthy and the majority will misuse any contact details for spam which users do not want. In fact there wouldn't be a business case (nor appeal to end-users) for Sign in with Apple if this wasn't a real problem.
- jjav 5y ago> Apple's SSO may not be eternal but it's also very unlikely to disappear overnight. If it is indeed going to be phased out you will have advance notice of this and a transition period. They may well offer notice and time when they cancel the service in some future. They won't offer any of that if they happen to erase your account just because though, as has happened to many people.
- fmajid 5y agoDon't forget in your threat model that Apple can cancel your account at any time for any reason whatsoever. They've even done it to security researchers using Apple's own bug bounty program. If that happens, you are stranded with those accounts effectively inaccessible to you forever. https://appleinsider.com/articles/21/04/20/man-sues-apple-for-terminating-apple-id-with-24k-worth-of-content https://appleinsider.com/articles/21/04/20/man-sues-apple-fo...
- Redoubts 5y agoHow does this threat model compare to using gmail or hotmail for your account access?
- nyuszika7h 5y agoSo? Google can also cancel your account at any time for any reason whatsoever, and good luck getting it back unless you're a celebrity with connections or manage to make a big enough fuss about it on social media. Using the same logic, you should not use Gmail then.
- pjerem 5y agoExactly, you should not use Gmail then. But that's off-topic.
- LadyCailin 5y agoIt isn’t though, because the developer had no problem offering that as a social login.
- cesarb 5y ago> Google can also cancel your account at any time for any reason whatsoever [...] Using the same logic, you should not use Gmail then. Actually, under that logic it's only that you shouldn't use the @gmail.com domain; it should be fine to use Gmail with your own domain, since that allows you to recover if your Google account is canceled (just change the MX to another email provider). Another thing you can do is to never use your Google account for anything other than email; that should reduce the chances of the account being canceled for no obvious reason. For instance, it's been reported that, if you used your Google account for Youtube, and Google decided your real name was not your real name (which it wanted due to the Google Plus integration with Youtube), your whole Google account could be canceled; that risk could be avoided by just never logging into Youtube with your Google account.
- jclardy 5y agoThen your issue isn't with Apple's SSO, it is with all SSO providers. Facebook/Google login are not eternal. The only difference is the proxy, which can be disabled. Any website offering SSO options would have a sunset period to move it over if a provider went under...and if they don't, they are likely defunct at that point anyways...
- elzbardico 5y agoApple may not be eternal, but probably will still be around for many decades after your app is completely forgotten. I still have the same IBM and Oracle accounts from the 90's. Big enterprises tend to stick around for a friggin long time.
- mrtksn 5y agoThere's a market for being anti-Apple that's not always based on reasonable ideas. It's popular especially among Web technologists, so maybe if your product targets them it could be a growth hack to "take revenge" and attack the Goliath, then create a literature around that "brave endeavour" that promotes your product.
- tonyedgecombe 5y agoIt’s popular amongst a few noisy individuals.
- shellac 5y agoPetty and hysterical. The part where the developer puts the word 'privacy' in scare quotes is a bit of a red flag for me. Suggesting that "accept[ing] two "social logins": Google and Facebook. All was well." does not fill me with confidence that the developer respects privacy concerns.
- raxxorrax 5y agoThese login methods are the least privacy preserving methods to do a login. The identity provider instantly knows which services you use.
- webmobdev 5y agoOnly the naive and the ignorant believe that Apple cares about users privacy. All their "privacy" features are just designed to collect more and more data about its users. Even unnecessary data. And they get away with it because of marketing that leads people like you to believe that they can be "trusted" with your data - the same data they use, and will use, to make more money. They have already restarted their advertising network again, like before. They claim they are no longer part of PRISM, a US government program that allowed big tech to sell user data to government agencies.
- deleted 5y ago[deleted]
- RL_Quine 5y agoThey implemented end to end encryption in iMessage to collect more data? There's a vast array of technical instances where apple has gone above and beyond to implement privacy preserving technology, even when they weren't talking about it. This is, like the OP, hysteria without any basis in fact.
- ksec 5y ago>They implemented end to end encryption in iMessage to collect more data? iMessage backed up on iCloud where Apple has key to decrypt.
- tomduncalf 5y agoAgreed, Sign In with Apple is a fantastic feature from a user point of view and I also think twice about signing up for an app which does not support it
- kraf 5y agoProtest is an important form of participation in a democracy, it's not petty at all. Forcing developers to add Apple ID as a sign-in method is the petty thing. The developers have no power unless they unionize in some form which seems absolutely impossible. So it seems to me that it's all a developer can really do to make a statement and I think it's brave.
- user-the-name 5y agoIt is not "petty", it is a way to ensure all users get access to a privacy-conscious method of logging in without giving up your privacy to Google or Facebook. Being this angry at having to give users the option of better privacy really isn't a great look.
- collaborative 5y agoNo one is forcing users to use Google or FB. They can do traditional email signup
- nyuszika7h 5y agoThat is definitely not true for every app. There was never any clause in the App Store guidelines that you must provide traditional email signup. At least this way, the social-only apps will be forced to provide you a more privacy-preserving alternative, and for ones that don't use social logins anyway, nothing changes.
- collaborative 5y agoOf course, my comment was related to the app of the post Groups specifically Which used to offer both social sign-up (FB and Google) and a traditional email sign-up option You probably don't know that in this case, Groups was also forced to include AppleID or risk being removed from the App Store Removing all social logins from this point to ensure compliance would have definitely affected all users who had originally signed in with FB/Google, way before AppleID ever existed
- karlkloss 5y agoI'm the opposite. I NEVER use a third party login, my it be Apple, Google, Facebook or whatnot. If your website/app doesn't offer their own independent login, I don't even think once whether I really need it.
- fmajid 5y agoAgreed. I find the mere sight of the Facebook or Google logo off-putting and resent the implication that it is a higher-priority login mechanism than email, a sort of act of fealty of the app/web developer to the big platform middlemen. I run my own mail server so it's easy for me to implement vendor-specific email addresses that cannot be correlated with other vendors', but more and more companies are offering that as a service nowadays, DuckDuckGo most recently: https://www.spreadprivacy.com/introducing-email-protection-beta/ https://www.spreadprivacy.com/introducing-email-protection-b... I do use GitHub federated login, but only for apps like vulnerability scanners that do need OAuth access to my repos.
- raxxorrax 5y agoI use them as a developer to offer it to users, not Apple though and not for apps. But I wouldn't want any of those companies know which services I use. I am fine with using Auth0 or other third party providers, but only if I have to. You don't even need to verify the mail in my cases, you could even use a completely fictious one. Clean, easy, anonymous. Not really sure about smartphone hell, but most identity providers offer up the mail of the user anyway. Maybe that is different in phoneland though.
- mattxxx 5y agoI think preferring to use the website/app's own login makes initial sense, but distributing your personal information around opens you up to more opportunities to get tracked/pwned/leaked/whatever. I used to prioritize the domain's own login, but now I'm starting to mix in some logins with Apple... I just prefer to have _less_ people have my personally identifiable information.
- CryptoBanker 5y agoAgreed, it screams two things to me. First that the company is supremely interested in collecting my personal information beyond what I would normally expect to provide. Second that they’re just too lazy to implement their own user system. Neither is a good thing
- webmobdev 5y agoNo, not at all petty. Kudos to the developer for standing up to the bullies that Apple and Google (and other tech companies) often are. Apple really needs to be reminded harshly that it is the developers that add value to their platform. And to share another perspective, I never use login from another service as it means you are sharing more data with them, and you become hostage to their whims and fancies they call their "terms and conditions". So if one day they don't like the app / service you have been using for whatever reason, they can bar you from logging into it without giving you any choice for it.
- wayneftw 5y agoApple is the most petty entity that I have to deal with on a regular basis. They refuse to automatically capitalize the words Linux or Windows but they'll practically force you to capitalize the phrase "app store" even though they don't have a real trademark on it. They'll try to change your vocabulary from "installing" to "side loading" just to protect their business model. They'll reject your app for looking too different. They're so petty that I think there's probably another word that I should be using to describe the level of pettiness that they've reached. Machiavellian perhaps.
- kec 5y agoThe autocorrect dictionary contains the name of every app on your device. It’ll learn Linux organically eventually, maybe Windows depending on how much home improvement you do….
- elzbardico 5y agoBefore apple introduced apple id, there was a annoying tendency of applications offering only third-party authentication from either google or facebook. Compared to Google or Facebook, Apple is definitely the lesser evil and an acceptable compromise between trusting Google or Facebook and the inconvenience of creating a login for every app. Forcing the implementation of Apple ID on applications that use other providers is actually increasing customer choice for me.