Seems a bit petty to me. As a developer I empathize with the possible lack of documentation (I don’t know, I never tried to integrate Sign In with Apple) but as a user I actually am super happy with it. Nowadays any iOS app that doesn’t support logging in with Apple makes me think twice about whether I really need the app.
Protest is an important form of participation in a democracy, it's not petty at all. Forcing developers to add Apple ID as a sign-in method is the petty thing. The developers have no power unless they unionize in some form which seems absolutely impossible. So it seems to me that it's all a developer can really do to make a statement and I think it's brave.
Nobody is forced to add Apple ID login if they don't have any other social logins. Personally I stick to direct signup but if I were forced to do social login, Sign in with Apple would be my first preference as it's the most privacy-preserving compared to Google, Facebook, Twitter, etc.
I wonder what it would take to "force" me into doing a social login? It would have to be something drastic, like a website that provides me with needed oxygen.
Anything else that would ‘force’ you to Have an Account somewhere, combined with that somewhere happening to outsource their identity framework to “social” of any kind. Or: the same things that would ‘force’ you to have a social network account to start with, potentially.
To get on my hobbyhorse some: what about a platform that your employer uses to distribute relevant documents and updates which you need for your job, which has become sufficiently well-known and implicitly available that hesitating about the dependency is perceived as bizarre?
Note that the response of “don't deal with them then” runs into market information and churn amplification¹ issues when it is a social assumption that picking up a ‘tool’ (which is actually a relationship with a third party, but where this is close to invisible in the steady state) is essentially a free action which requires no consideration, because the information about “does this employer require me to use this tool” neither propagates efficiently nor stays stable.
Past source: wound up changing the email address on one of my Google accounts recently for exactly that reason. They actually asked me up-front whether I had a GMail account they could use instead, which turned out to be because they use restricted Google Docs for critical material. Not naming them, but in a broad sense, this is one of the more ethical companies I've ever dealt with, by the way.
Future source: I should probably be considering digging into LinkedIn soon despite their past abusive behaviors, because as it turns out, if I want to dig myself out of this hole…
¹ I assume there's a ‘real’ term for what I'm thinking of, but I don't know what it is, so I cobbled that one together out of the most relevant-seeming bits.
Apple is extremely restrictive to developers. As a developer, I hate it. As a consumer, I love it.
Apple has never shown me hostility. On the contrary, I found Apple to offer reasons why they do things and how to work around them. Have they sometimes forced me to do things I don't want (and felt were worse)? Yes. But it was obvious what I needed to do to comply.
For example, this whole forcing devs to use "sign in with Apple" is not about imposing restrictions as you can decide to not use a third party sign in (on a new app).
Apple is saying "hey if your users can sign in with Facebook they should be able to sign in with Apple, we want a piece of the pie". Some iOS users are happy about the privacy aspect of this but fundamentally (IMO) this is not about privacy or restrictions, it's about making users and devs more dependent on the Apple ecosystem.
What's the "pie"? FB makes money off their data. Apple seems to be providing me the service I paid for.
If they made it optional, a large percentage of apps would force you to use Google/FB to login. That's not acceptable to me.
One of the major reasons I give Apple money is to because they can stand up against the privacy invading FB/Google and I, as an individual, cannot. So they are very much doing what I want in this instance.
If a dev uses a Facebook login on an app then it will never be able to remove it again as users won't be able to log in. Similarly, if it uses Facebook comments, these cannot be removed from a website as the content would be lost.
Apple does the same thing. As a dev once you open the door to using Apple you're forever stuck with that. As a user, it entrenches you further into the Apple ecosystem which is ultimately the whole Apple product strategy.
I don't really think lock in is Apple's primary goal. I think they are opposed to Google/FB spying on us, and therefore there has to be an alternative. You don't have to implement Apple SSO, you just cannot use any other SSO without adding it as an alternative.
Again, the point that you as a developer are missing is that your behavior is atleast as, if not more abusive towards your end user than Apple are being. Why should your user have to use an anti-privacy 3rd party like Facebook to use your app or service? Where is the users choice other than to not use your product?
I have to be honest here and say that I amazed, but sadly not surprised by the level of entitlement on display from a very small but extremely vocal set of developers.
It is not "petty", it is a way to ensure all users get access to a privacy-conscious method of logging in without giving up your privacy to Google or Facebook.
Being this angry at having to give users the option of better privacy really isn't a great look.
That is definitely not true for every app. There was never any clause in the App Store guidelines that you must provide traditional email signup. At least this way, the social-only apps will be forced to provide you a more privacy-preserving alternative, and for ones that don't use social logins anyway, nothing changes.
Of course, my comment was related to the app of the post Groups specifically
Which used to offer both social sign-up (FB and Google) and a traditional email sign-up option
You probably don't know that in this case, Groups was also forced to include AppleID or risk being removed from the App Store
Removing all social logins from this point to ensure compliance would have definitely affected all users who had originally signed in with FB/Google, way before AppleID ever existed
>Removing all social logins from this point to ensure compliance would have definitely affected all users who had originally signed in with FB/Google, way before AppleID ever existed
Yet it would have been more consistent! What is the point of going to war against Apple while embracing the private-data-broker model at the same time?
Just send a warning e-mail requiring password change because you decided to remove all social login as a protest.
And provide a password reset mechanism for formerly social-login users that haven't defined a password in time.
But Apple is forcing devs to include Apple ID and that's what's wrong here. They could have made it optional. Given how Apple users can be it likely would have ended up being in demand and devs would have included it out of their free will
There is basically no benefit to app developer in including it. It is more work, and you may get only an anonymised address. However, there is massive benefit to actual users.
Apple decided to prioritise users over developers here.
Trust me, I say this as a developer, if there is any indication that I am losing out on users because I don't have Apple ID, I will make sure to add it asap. That is pretty much the reason why I first included FB and Google. I first only had Google, then some people aksed for FB. The natural course would have been that then some other guys ask for Apple and I add it. But Apple decided to abuse its position and force it on us developers
Yes. It is important that more developers stand up to this kind of bullying. Apple needs to respect developers more and, if it wants them to integrate Apple services they should instead offer incentives rather than threats to them. As both a developer and an Apple user, I don't care about Apple ID and so why would I wish to waste my precious time adding features I am not interested in? (I use Apple products but I never use Apple ID anywhere because I believe it weakens my privacy - why would I want to share more personal data with Apple, a company that was part of PRISM and used to sell user data to the government?)
Equally, developers need to respect their users. I don't want to have to have a Facebook or Google account to use your product. Why should I be interested in your app if you force me you use either of those options? They were also involved in PRISM and both have far worse track records with privacy than Apple. More importantly, why should I trust you with PII?
Having your email address boils down to password recovery. For instance, I only ever send 3 types of emails:
1 - Activation email with activation code to ensure the person actually owns the email address (non-OAUTH sign-up)
2 - Password recovery for when they have forgotten their password. Yes, a user doesn't need this with OAUTH but sometimes they will have forgotten that they used OAUTH to start with and need to sign in with email & pss
3 - When push is turned off and someone has messaged you
I don't think this is beyond reasonable but I'm willing to take criticism
> Having your email address boils down to password recovery. For instance, I only ever send 3 types of emails
I don't care. I don't trust you. I don't trust any of modern devs, I see every other new shiny crap on the internet only as an attempt to extort me of data and/or money (subscription) now. Before Apple introduced that feature I was using email aliases in my Fastmail. Need to register in new service - go to Fastmail, generate an alias for some weird domain they've got, setup filter for it to go to "dodgy" folder and then register.
Now I don't need to do that anymore, Apple automated that for me.
And thank's Apple it also forced guys like you to allow me to use that automation. At least on their platform.
For same reason the only way I buy a subscription is through an in-app-purchase - because I can just to go App Store and cancel it and don't need to deal with people like you. I remember like an year ago I was waiting for a refund for a cancelled subscription and my emails were ignored and the only way to get the attention was to open a dispute in PayPal. Yet another supplier-hostile but consumer-friendly company. Thanks god they exist.
I think some smaller-time devs don't appreciate that if they "win" against Apple and make them significantly loosen restrictions, users' wallets will tighten, especially for small developers and companies that no-one's heard of. Keeping the App Store low-friction, low-risk, and UX consistent, is a huge benefit for those kinds of devs (the ones selling software or subscriptions, anyway).
The messages sent to the "anonymous" Apple id mail are just forwarded to the user's inbox, aren't they? How is that any different from any other email address.
There is an email origin restriction- that's how they keep devs from selling them, emails can only come from the right domain. That still shouldn't be a problem though.
It isn't. My problem with AppleID is nothing more than that they forced AppleID on me. I would have voluntarily added it otherwise. But now because of this, I really really dislike it to the point that I will refuse to implement it in other platforms where it is not mandatory
And I think Apple's behavior should change so I am making this public
Asking an honest question: if Apple didn’t force this, would you really add this voluntarily?
Because this response tells me you’re willing to compromise your user’s experience because of your personal issues with Apple.
As a user, this does not give me confidence in your decision making.
It’s somewhat understandable to be annoyed, even angry at Apple. But the moment you decide to pass that on to your users is the moment you’ve forgotten the most important humans in this story.
Of course, it’s your right to do what you want, and if that means taking a stance against Apple ranks higher than your user base, I suppose that’s your prerogative.
But that definitely would make me hesitate to use the app.
I don't even hold a grudge against Apple. This is just me trying to make the world a better place. It's in everyone's interest that Apple doesn't gain authority to force us to do things (don't forget, devs also are Apple customers)
On the other hand, I absolutely trust Apple - my relationship with them spans over a decade and countless products/experiences.
I’m happy that they’re forcing devs to offer Apple Sign On as an option when other social logins are also offered. As a user, I trust Apple far more than any 3rd party dev.
I pay a premium to Apple because of their platform and the types of things they enforce.
I want you to understand that as a user, this is exactly what I want Apple to do and I pay extra for it.
But what you're telling me is that your opinion about Apple here supersedes my own wishes/wants/goals as an end-user.
This reads like "I know what's best, despite what Apple users say they want, and I'm going to make the world a better place by ignoring my users and telling them what they want is actually bad for them", despite the fact that this is actually a beneficial feature to users, even if it could be construed as a benefit to Apple as well (arguments can certainly be made).
> It's in everyone's interest that Apple doesn't gain authority to force us to do things
The rulebook to participate in this ecosystem is a mile thick. Why is this the issue that you choose to make a fuss over? There are a a myriad of other rules that are even more heavy handed, that actually are to the detriment of end users to protect Apple's walled-garden.
Picking a feature that arguably makes user's lives better seems tone deaf at best, and actively harmful to a broader message about openness at worst.
The thing is, Apple only 'force' you to add their option if you have an app on the store and offer another form of public federated identity provider. If you don't want to offer Apple as an option, then don't offer anyone else. Look at the context of why they have enforced it. Privacy is hard. The concern is that that the majority identity providers/brokers in use are Facebook and Google. I'll happy listen to the 'competition' argument as it does have a little merit. However, when weighed up against the notion that these two are the only real choice for a significant volume of apps, it is extremely worrisome from a privacy point of view. Neither have a reason to respect end users, or you as a developers privacy because that's how they make money.
Petulance does not become a developer. The last time I saw a tantrum thrown this much was when my kid was 5 and had a major meltdown over a lack of chocolate ice-cream.
He didn't get any ice-cream for a week, a response that taught him meltdowns don't work.
You can judge my post as a tantrum, and I won't even take offense, friend
Now I ask you this: how far are you willing to go to further a good cause? Watching from the sides feels more comfortable, but we are being decimated and doing nothing won't change a thing. We need to act now, or watch our profession/hobby/passion be used to fatten the already morbidly overweight big tech companies
> how far are you willing to go to further a good cause?
But what, exactly is the "good cause" here? Is the good cause to force Apple to stop delivering an experience that we've already established throughout this thread is an experience Apple users want?
There are so many problems and battles to be fought in tech, so much abusive behavior, so many dark patterns. This is not that. If this is the cause you're fighting, I fear you've missed the forest through the trees.
Unless you had something else in mind, in which case I'm genuinely curious.
What is the “good cause” here? You’re just being user hostile and fighting a feature that is highly beneficial for users! If anything, it is Apple that’s fighting a good cause here.
Does something being beneficial for users justify anything?
Enslaving the entire Uber driver or deliveroo poor sod population is arguably beneficial for users. But, is it right? Plenty of jurisdictions have already spoken that these workers have rights. Nobody has made a ruling regarding developers yet
The "iMentality" can't possibly extend to wishing that Apple treats other human beings like **. Can it? If so, we may have gone back in time to even before the 1860s
You're underestimating email. People reuse their email address, so it's not as benign as you think.
Just googling someone's email is a start. But worse actors can find your email on a combolist or figure out what other services you use. Just knowing someone's email is the first step to social engineering a customer service backdoor, for example.
AppleID specifically helps users avoid all this with trivial per-app email address generation, and that's something our tools should have given us a decade ago.
Yes, developers need to respect users too. But that should be between the developers and the user. If a user asks me to add Apple Id as an option in an app I make, that is something that I would seriously consider as I care about my users. Why should a developer care about something no user has requested but Apple is forcing them to use?
Apple could be considered a genuine neutral arbitrator if it didn't take money from both the developers and its users. What it has done instead is to force itself between the user and the developer, and exploiting both in the name of the users (developers lose money to Apple's extortion, and the money it extorts from the developers is ultimately passed to the user, and thus they end up exploited too).
The bizarre thing is the ignorance here that this whole thing is a matter of choice! I am glad that there are developers who recognize that they do not have to accept unfair, and even unethical, practices from corporates. And are willing to speak about it and fight it.
Like minded developers are not just fighting Apple, but the whole attempt by "big tech" to move to the business model of exploiting developers by controlling distribution of softwares, and dictating terms that favour them. This ends up harming both developers, as they earn less, and users, as ultimately it the user who ends up paying the share of profits that Apple (and others) extort from the developers.
It doesn't work like that. Users can't ask about options they don't know about.
And even if they do, too many developers couldn't give two shits. Great example is how users overwhelmingly opt-out of tracking when the OS warns them about it (because "developers thinking about users" never even considered not tracking)
I'm the opposite.
I NEVER use a third party login, my it be Apple, Google, Facebook or whatnot.
If your website/app doesn't offer their own independent login, I don't even think once whether I really need it.
Agreed. I find the mere sight of the Facebook or Google logo off-putting and resent the implication that it is a higher-priority login mechanism than email, a sort of act of fealty of the app/web developer to the big platform middlemen.
I run my own mail server so it's easy for me to implement vendor-specific email addresses that cannot be correlated with other vendors', but more and more companies are offering that as a service nowadays, DuckDuckGo most recently:
I use them as a developer to offer it to users, not Apple though and not for apps.
But I wouldn't want any of those companies know which services I use. I am fine with using Auth0 or other third party providers, but only if I have to.
You don't even need to verify the mail in my cases, you could even use a completely fictious one. Clean, easy, anonymous.
Not really sure about smartphone hell, but most identity providers offer up the mail of the user anyway. Maybe that is different in phoneland though.
I think preferring to use the website/app's own login makes initial sense, but distributing your personal information around opens you up to more opportunities to get tracked/pwned/leaked/whatever.
I used to prioritize the domain's own login, but now I'm starting to mix in some logins with Apple... I just prefer to have _less_ people have my personally identifiable information.
Agreed, it screams two things to me. First that the company is supremely interested in collecting my personal information beyond what I would normally expect to provide. Second that they’re just too lazy to implement their own user system.
To the average user, social login is about convenience. I see a large number of responses in this thread that seem to have forgotten about the most important person in this whole conversation: the end-user.
Users want
- Easy access
- A familiar experience
- A consistent experience
- To avoid more passwords
They generally are not aware of the privacy tradeoffs they're making by using social login.
I'd argue that if the developer truly wants to fight the good fight, they should remove social login altogether.
I find it odd that the options they support willingly are the options that are most user-hostile from a privacy perspective while the option they begrudgingly support (while making a big fuss about it) is the one option that actually tries to protect the user.
You clearly don't understand how social logins work, nor their benefits for users and site owners. Both of your assertions are wrong, and both "bad" things are exactly the opposite.
You don't get anything beyond what you ask for AND are granted access to by the user.
FB login gives email and name AFAIK, but you can ask for lots of other stuff and be denied. Google defaults to email, not sure about name, and has separate requests and grants for any additional information. They don't have nearly as much of a profile as FB does, but can give address and some other details. Apparently Apple doesn't even provide a real email, so that seems even better for "collecting [your] personal information" than using... your personal email address!
Social login is much better than storing passwords in any form (plaintext, encrypted, hashed), and gives both the user and site owner the benefit of FAANG security.
The part where the developer puts the word 'privacy' in scare quotes is a bit of a red flag for me. Suggesting that "accept[ing] two "social logins": Google and Facebook. All was well." does not fill me with confidence that the developer respects privacy concerns.
The reason "privacy" is in quotes is that some of us have started seeing through what Apple really means every time they use the word. As the EU's Executive Vice-President Margrethe Vestager has recently said regarding their Apple probe, privacy can't be an excuse to stifle competition.
All was well because nobody was forcing me (the developer) to include anything I didn't want. Users could still use traditional email signup. You are free to choose whom you trust. If your choice is Apple, well, that is your choice
Indeed it is. And I would choose to trust Apple over some nobody on the internet with a seeming chip on their shoulder (seriously, that post is just cringe) over anyone who promoted Facebook and (to a lesser extent, obviously) Google as sign-in methods.
In. A. Heartbeat.
You claim (elsewhere) that you only send responsible-sounding emails, but the level of invective in your screed leads me to disbelieve you. Personally, I think HME seems to have been created exactly to cope with people like you - and I’m failing to see this “hype” you talk about.
HME makes the value of an email address tend to zero, gives me the ability to cut you off without your agreement (and prevents you from selling my email on afterwards), and places all the control in my domain not yours. That’s simply the truth of the matter, and it’s not hype.
I distrust anyone who tries to downplay privacy as important.
I distrust anyone who tries to brand a genuine privacy upgrade as "hype"
And, frankly, signing in (with AppleID or not) doesn't prove a thing one way or another. The OP could be simply harvesting email addresses and selling them off later[+]. (S)he could be upset that HME and SIWA are a threat to that business. Far-fetched ? Sure. More far-fetched than an adult throwing the tantrum on the website ? Not so sure...
Or another option along the same lines. Perhaps OP has another more-public site that (s)he doesn't want to take this stand on for PR reasons, so they're doing it here, and getting "awareness" out there by submitting to places like HN. In that case, sure, there'd be no email abuse on the <don't care about> site...
There's a few other options that are possible. None of these get around the basic premise that privacy on the net is important (at least to me, YMMV) and I don't trust those who decry it.
[+] Tesla does this, for example. All of a sudden, a couple of years after buying power walls, I'm getting emails to Tesla@<my-domain> and texts containing Tesla@<my-domain> to my phone number (which I usually obscure using google-voice) asking if they can give me mortgage offers (for example). Tesla sold my details when I stopped buying expensive stuff from them - this is why I set up a catch-all address, and used <company>@<my-domain> whenever I signed up for stuff. Now I use HME.
>I distrust anyone who tries to brand a genuine privacy upgrade as "hype"
I particularly like this Apple fanboi argument - that having a third party (Apple) needlessly involved is somehow more "private" than only just the 2 primary parties being involved.
>I'm a Brit
Well I guess that explains a lot then - you're probably one of those that also voted for brexit, but now completely denies it - right?
It's funny - it always seems those who use "fanboiz" or other collective terms akin, always seem to be projecting...
They don't seem to be able to grasp that maybe there are different viewpoints in this world. Maybe that's even a good thing, and perhaps denigrating entire swathes of people as "fanboiz" says more about the person doing it than about the people they're complaining about.
Offering Apple as a choice does not remove the customer's ability to use the two biggest names in surveillance capitalism as the "protector" of their privacy.
Only the naive and the ignorant believe that Apple cares about users privacy. All their "privacy" features are just designed to collect more and more data about its users. Even unnecessary data. And they get away with it because of marketing that leads people like you to believe that they can be "trusted" with your data - the same data they use, and will use, to make more money. They have already restarted their advertising network again, like before. They claim they are no longer part of PRISM, a US government program that allowed big tech to sell user data to government agencies.
>“We specifically don’t collect data, even from point A to point B,” notes Cue. “We collect data — when we do it — in an anonymous fashion, in subsections of the whole, so we couldn’t even say that there is a person that went from point A to point B. We’re collecting the segments of it.
The segments that he is referring to are sliced out of any given person’s navigation session. Neither the beginning or the end of any trip is ever transmitted to Apple. Rotating identifiers, not personal information, are assigned to any data or requests sent to Apple and it augments the “ground truth” data provided by its own mapping vehicles with this “probe data” sent back from iPhones.
>An Associated Press investigation found that many Google services on Android devices and iPhones store your location data even if you’ve used a privacy setting that says it will prevent Google from doing so.
"The iPhone continues to store location data even when location services are disabled, contrary to Apple’s previous claims. The Wall Street Journal did independent testing on an iPhone and found that even after turning off location services, the device was still collecting information on nearby cell towers and Wi-Fi access points."
"The best way to keep something secret is not to capture and store it in the first place. And that’s the crux of the privacy versus convenience debate now redefining our applications and software-based services ... Yes, maybe what happens on an iPhone stays on an iPhone, but some data should not be captured in the first place. Nothing more so than the significant invasiveness of Apple’s significant locations concept—a perfect illustration of just because you can, doesn’t mean you should. This is a continually building data repository of the locations you visit, along with times and dates, detailed maps, even the mode of transport to get you there and how long it took."
“Both iOS and Google Android transmit telemetry, despite the user explicitly opting out of this,” wrote researcher Douglas Leith from Trinity College in Ireland, in a recently published academic report ... “To date, Apple have responded only with silence (we sent three emails to Apple’s director of user privacy, who declined even to acknowledge receipt of an email,” Leith wrote. Since then, Apple has made public statements critical of Leith’s research and insisting privacy and opt-out measures do exist.
"And there’s also a more fundamental issue with this technology. Its euphemistic description as a “crowdsourced” way to recover lost items belies the reality of how these items are tracked. What you won’t find highlighted in the polished marketing statements is the fact that AirTags can only work by tapping into an Apple-operated surveillance network in which millions of us are unwitting participants."
As for "anonymising" user data, Apple has enough data points on its users from various services and sources it collects its user data from to make it meaningless.
They implemented end to end encryption in iMessage to collect more data? There's a vast array of technical instances where apple has gone above and beyond to implement privacy preserving technology, even when they weren't talking about it. This is, like the OP, hysteria without any basis in fact.
Well, kind of. Apparently Messages in iCloud is still E2E encrypted, but not if you have full-device iCloud Backup enabled. Though I've often been prompted for my previous passcode to restore data from an iCloud backup, so not sure if anything has changed on that front.
Apple is a capitalistic company, they are not saints. But part of their business model selling hardware and software is partly based on at least maintaining a minimal level of decency, far above what Google and Facebook practice.
I don't agree with that view point. As both a user of Apple's products and as a worried citizen about privacy rights, to me it looks like Apple is just using a different approach to collect the same user data that Google and Facebook desire. It is just using the hindsight of how Google and Facebook went about it, and the negative PR they faced, to refine both its data collection process and PR strategy to convey they are saints. (It's a classic Apple way - they observe their competitors and their product for a while, before refining it and launching their own).
There is a lot of profit in collecting and monetising user's data - Apple's shareholder will not allow them to leave it on the table. Apple knows that as it was part of the PRISM program and earned a lot of money by supplying the US government it's users data. (Apple also dropped plan for encrypting backups after FBI complained - https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... ). And on a different note, in the early years, Google too begin it's spying and data collection by convincing its users that it is a "decent" company.
> Nowadays any iOS app that doesn’t support logging in with Apple makes me think twice about whether I really need the app.
I agree. I only create accounts for things reluctantly. Because 1. Why do you want my email address, or DOB, or whatever else? I don't want your marketing, and 2. I can't be bothered, I downloaded your app because I have something I want to get done.
Because Apple's SSO will not be eternal and nobody wants to have a tier as a proxy on an important account credential.
Apple SSO is ok for throwaway account where your account has no "sentimental value" that you can't recreate easily. But the author of this post maintains a social network : nobody wants to be locked out a social network.
I have active accounts on websites that existed back when Apple was fighting not to die and I would have totally lost access to them if I had to sign-in to them through my Lycos account.
Sign In with Apple allows you to share your email so you are incorrect. If I decide to hide my email and be locked out - my choice. Developers and companies are greedy for data. Why do we have the expectation that emails should be shared? I constantly say don’t send me marketing and some services send. On my part I report them as spam every time so that algos start blocking them as they are breaking our contract and are malicious.
For every service I’ve built allow the user to create an account with email, Google, Microsoft, Apple, Twitter, Facebook and to later untie their account and move to email. Also if they ever get locked out from their oauth account they can use the email to create a password and login via the normal way.
> Also if they ever get locked out from their oauth account they can use the email to create a password and login via the normal way.
This is exactly my point ! You can't recover your account if you don't know the mail used for registration. Even if you remembered it, no check could be made if Apple stopped to proxy the mails for one or another reason.
With other providers, you could always recover an account because your email address would let you prove the ownership of the account.
You can look up any private relay email address you've had provisioned in iCloud settings. It shows what service it was used or and the email, also allowing you to disable the address. This is also available from the Apple ID manager:
Is that not the same with if Google block my account? I won't be even able to login to my email for simple password reset or to verify I'm the actual owner of the email.
This is the problem with one click account vs email entering. It is a risk users should be made aware of but it is still their choice. And for some critical services I'll use my email, for other like the app in question, or most apps on the App Store I'll use one-click install, also most of the time there is no need for me to have an account. Most data can be stored on device without the need for user authentication.
I was under the impression that the Apple email that you get is not a real email address with an inbox? Is it? How can you verify a user the real owner of the email?
If they are locked out of the oauth account, presumably they can't check their inbox.
edit: Oh, do you mean you ask for an email address after they already flow through the oauth process - because that's the worst of all :)
The Apple-provided e-mail address forwards to their real email, so you can still use it for e-mail verification and communications. It just means the user can deactivate the alias at any time and stop further spam.
Don't forget in your threat model that Apple can cancel your account at any time for any reason whatsoever. They've even done it to security researchers using Apple's own bug bounty program. If that happens, you are stranded with those accounts effectively inaccessible to you forever.
So? Google can also cancel your account at any time for any reason whatsoever, and good luck getting it back unless you're a celebrity with connections or manage to make a big enough fuss about it on social media. Using the same logic, you should not use Gmail then.
> So? Google can also cancel your account at any time for any reason whatsoever
Right, that's why. Don't ever use "sign in with XXX" for any value of XXX, whether apple or google. Any of them can erase you off their site on a whim and you've lost all unrelated accounts where you made the mistake to "sign in with XXX".
Create accounts with your own email, control your future destiny.
> Google can also cancel your account at any time for any reason whatsoever [...] Using the same logic, you should not use Gmail then.
Actually, under that logic it's only that you shouldn't use the @gmail.com domain; it should be fine to use Gmail with your own domain, since that allows you to recover if your Google account is canceled (just change the MX to another email provider).
Another thing you can do is to never use your Google account for anything other than email; that should reduce the chances of the account being canceled for no obvious reason. For instance, it's been reported that, if you used your Google account for Youtube, and Google decided your real name was not your real name (which it wanted due to the Google Plus integration with Youtube), your whole Google account could be canceled; that risk could be avoided by just never logging into Youtube with your Google account.
Google isn’t worth the trouble.
I pay for my email, you remember paying for stuff you use, an antiquated idea, I know, but restores the balance in the equation.
Apple's SSO may not be eternal but it's also very unlikely to disappear overnight. If it is indeed going to be phased out you will have advance notice of this and a transition period.
I agree that in a perfect world you'd provide your real email address and solve this problem. But developers and companies have repeatedly proven themselves to not be trustworthy and the majority will misuse any contact details for spam which users do not want. In fact there wouldn't be a business case (nor appeal to end-users) for Sign in with Apple if this wasn't a real problem.
> Apple's SSO may not be eternal but it's also very unlikely to disappear overnight. If it is indeed going to be phased out you will have advance notice of this and a transition period.
They may well offer notice and time when they cancel the service in some future.
They won't offer any of that if they happen to erase your account just because though, as has happened to many people.
Don’t use apple SSO because apple might not exist one day?
You may as well argue not signup to anything using gmail because, heck, google might go out of business.
There is no benefit to users in giving your “real” details to service providers; the benefit is entirely on their side.
You can argue that Apple is harming the opportunities for 3rd party developers, sure, taking advantage of them? Sure.
…but let’s not try to frame this as somehow “pro consumer” to give your email away so people can spam you with notifications and offers to lift their engagement rates.
I don't think your tone is warranted and in the spirit of this community.
I don't agree with GP's fear of Apple SSO vanishing without a transition period to something else, but the general premise that this form of login is not eternal but rather short lived in the grand scheme of things is reasonable and doesn't warrant your aggressiveness.
Also you might get locked out of your Apple account for a number of reasons and will then lose access to much more than just Apple services.
It is also not really a valid argument here, given that the service we are talking about was offering Facebook and Google login options, which share the exact same issue, but with the added privacy violations of those platforms.
From what I understood from these discussions, that is not an issue with Facebook and Google logins because they reveal the true user email address, so even if they no longer exist one day, that email address could be used to recover the user accounts (using a password recovery flow through email); while Apple SSO does not reveal the true user email address, only a proxy through Apple's systems, so if it no longer exists one day, there's no way to use the email address to recover the user accounts.
Apple asks the user whether they want to reveal their email or not. If you do not receive a real email address for Sign in with Apple, it is because the user did not want to give it to you.
>Don’t use apple SSO because apple might not exist one day?
>You may as well argue not signup to anything using gmail because, heck, google might go out of business.
I assume OP point is that Apple or Google could still exists but your accounts might not exist, maybe you get banned or just decide you don't want to use Apple/Google/FB anymore.
> Don’t use apple SSO because apple might not exist one day?
There might be a day when Apple is not _my_ cell phone platform. Even now I have an Android phone and iPad and I prefer to have access to same services from both.
Yes, or at least not with a @gmail.com domain. Running Google Apps with a custom domain you own and Google can't snatch away is fine (well, apart from the privacy implications of giving Google free rein to read your emails, of course). That means not using Google as your registrar, obviously.
> You may as well argue not signup to anything using gmail because, heck, google might go out of business.
I personally avoid to do it, but that's not the point.
Every other third party allows account recovery by mail : if you want to stop using FB or Google's SSO, you can ask the website to send you a mail to prove the account ownership.
If Apple's SSO stopped working (because Apple stopped it, banned you, because you dont have Apple devices anymore so you are locked out of their proprietary 2FA), none of those websites could send you a recovery email.
> That is pure BS.
I don't feel like I've been insulting, so please don't be either.
> because you dont have Apple devices anymore so you are locked out of their proprietary 2FA
They have SMS as a fallback. I know it's insecure and I'd rather they support TOTP, but let's not pretend having an Apple device is the only way to receive 2FA codes for your Apple ID.
> Don’t use apple SSO because apple might not exist one day?
Yes. And more to the point, because that Apple service may not exist in the future. Or Apple may determine that a particular app or service can no longer use its service for whatever reason, and you as a user will not have any choice in that manner. It's all been done before.
And it makes me think : what happens to the "proxy emails" affected to your application when Apple decides to ban your app from the App Store ? Are your users still reachable ? Is there any information on this ?
Given an alternative storyline where Epic Games allowed users to create account with relayed apple mails, wouldn't all those accounts suddenly became unusable today ?
Epic actually did allow users to use SWA since they have about 5 other IdPs they allow. Apple didn't suspend their access to SWA at any point, though there were stories about it at the time.
Then your issue isn't with Apple's SSO, it is with all SSO providers. Facebook/Google login are not eternal. The only difference is the proxy, which can be disabled.
Any website offering SSO options would have a sunset period to move it over if a provider went under...and if they don't, they are likely defunct at that point anyways...
Apple may not be eternal, but probably will still be around for many decades after your app is completely forgotten. I still have the same IBM and Oracle accounts from the 90's. Big enterprises tend to stick around for a friggin long time.
Agreed, Sign In with Apple is a fantastic feature from a user point of view and I also think twice about signing up for an app which does not support it
Before apple introduced apple id, there was a annoying tendency of applications offering only third-party authentication from either google or facebook.
Compared to Google or Facebook, Apple is definitely the lesser evil and an acceptable compromise between trusting Google or Facebook and the inconvenience of creating a login for every app.
Forcing the implementation of Apple ID on applications that use other providers is actually increasing customer choice for me.
There's a market for being anti-Apple that's not always based on reasonable ideas. It's popular especially among Web technologists, so maybe if your product targets them it could be a growth hack to "take revenge" and attack the Goliath, then create a literature around that "brave endeavour" that promotes your product.
Apple is the most petty entity that I have to deal with on a regular basis. They refuse to automatically capitalize the words Linux or Windows but they'll practically force you to capitalize the phrase "app store" even though they don't have a real trademark on it. They'll try to change your vocabulary from "installing" to "side loading" just to protect their business model. They'll reject your app for looking too different. They're so petty that I think there's probably another word that I should be using to describe the level of pettiness that they've reached. Machiavellian perhaps.
The autocorrect dictionary contains the name of every app on your device. It’ll learn Linux organically eventually, maybe Windows depending on how much home improvement you do….
No, not at all petty. Kudos to the developer for standing up to the bullies that Apple and Google (and other tech companies) often are. Apple really needs to be reminded harshly that it is the developers that add value to their platform. And to share another perspective, I never use login from another service as it means you are sharing more data with them, and you become hostage to their whims and fancies they call their "terms and conditions". So if one day they don't like the app / service you have been using for whatever reason, they can bar you from logging into it without giving you any choice for it.