1. Services have little incentive to support mailinator, and indeed may deliberately choose not to if they feel it is leading to signups they don’t like. On the other hand it would be hard to argue with an incentive like the App Store requiring you to support apple’s service.
2. Because the service is built in to apple’s systems there seems to be an implicit contract that apple wont let it be abused for the purposes that many sites claim mailinator is used for (because it isn’t useful to apple customers if sites don’t trust it and it). So they might be more willing to accept these email addresses.
I guess neither of these help services like mailinator gain credibility.
I have been responsible for creating and maintaining an app generation system. Among other things, it taught me that App Store Connect has many sharp edges showing how easy it is to abuse the kind of power you've correctly pointed out Apple has.
And this effect is massive last week I offered two of my old laptops to a friend child wanabee hacker. He quickly considered a 2012 HP for parts, then he kept on thanking me for a working state 2002 PPC iBook.
PS: To be honest he might be ranting about it in a few day, I’ve played around it a little and that 2002 iBook bios is a mostly undocumented nightmare!
The battery glue is like a 3M command strip, you're supposed to remove it by applying tension to the side. You need the heat source if the strip breaks and gets trapped underneath, but I used dental floss instead.
I'm not sure how this is manipulating to get me to purchase a new phone.
That's disingenuous. Apple has a recycling program, where they take apart every component to be reused or recycled into new materials.[1]
[1]: https://www.apple.com/newsroom/2018/04/apple-adds-earth-day-...
7.8 million "Apple devices"[0] in 2018 is a lot, but an average iPhone is far more likely to end up on a landfill. If it were easy to extract the battery, that wouldn't be such a problem.
[0] They group them all together and I can't find any other metric: https://www.apple.com/newsroom/2019/04/apple-expands-global-...
It's perhaps less evil than the kind of wholesale data-farming the other big tech companies are engaged in, but it still doesn't make me like the idea of Apple ascendant.
And I was raised on Macs, giving Apple a heavy nostalgia bonus that they burned years ago.
You find that you're being strongarmed. As a oonsumer, I could not care less. Hell, I am thrilled that developers are being strongarmed when it comes to user privacy and security.
I am concerned with things like Apple's terms of service saying "If you put an app in the store, we reserve the right to copy it and ban yours."
They don't spell it out quite that clearly, but sections 14.4 and 11.2 of the developer guidelines make it clear enough (https://download.developer.apple.com/Documentation/ADP_Progr...).
Yes, there are more charitable interpretations possible, but Apple does have some history of cloning and killing off third party software, so I see no reason to apply the more charitable interpretation.
Who said the Windows/Android model is the morally correct one anyway?
As a customer I'm glad that Apple is providing a truly different alternative.
I'm not scared of this anonymous signin feature, per se.
I'm scared of the sheer amount of power Apple has, and that they can abuse it to force third parties into compliance with what they think software should be.
That's what I was saying I found terrifying.
"In order to send email messages through the relay service to the users’ personal inboxes, you will need to register your outbound email domains. All registered domains must create Sender Policy Framework (SPF) DNS TXT records in order to transit Apple's private mail relay. You can register up to 10 domains and communication emails."
The attacker wouldn't even be able to send e-mail messages to the users. He'd also need to compromise the registered domain's mailservers, or their DNS servers (to modify the SPF records), or their Apple dev account to add their own registered domain.
And, they have the money to do it.
For as long as Android has google ownership... they will never, ever be able to compete on the level of privacy that Apple is now buying into.
https://addons.mozilla.org/en-GB/firefox/addon/idbloc/
https://chrome.google.com/webstore/detail/idbloc-secure-and-...
With Idbloc (and apple sign in) the address is completely random and untraceable, and it’s impossible to tell which addresses belong to which users.
That's something I really dislike. Perhaps it's a necessary evil.
The goal is to explain the concept ahead of the pricing as I think it’s quite novel to most users.
I think it’s great, and use it a lot. Just wonder how you got to that price vs like $10/year.
That and people pay 4 bucks for a coke these days so it’s not really much. Also cPanel is most definitely an expert tool.
I might make it paid only soon and reduce the price but at present there’s not much option to get real feedback and user traction.
$4 is not very much, you’re right, but that doesn’t mean that it should be spent unwisely otherwise it adds up quickly. It seems unlikely that this would need a full time dev to operate and seems more like a “4 hour workweek” type business once it’s set up that would have pretty minimal maintenance, or a super bored developer waiting around for a bug to patch.
Do you think you’ll drop the price once you no longer need a dev?
Except it’s not real time until a support person is notified and responds minutes or sometimes hours later. Chat pop ups feel like a lame trick these days every time I try to use them; they pretend like they’re going to be fast and then make you waste your own time waiting. The last one I used the other day made me wait more than 10 minutes, so I did something else, and when the support person responded and asked a follow up question and I didn’t answer in 5 seconds, they closed the support ticket, making me start over. I’d rather use email.
I usually email them after, too. "I actually clicked through your instagram ad, looked at some clothes that looked nice, and didn't buy anything because I was on my phone and didn't want to make a new account and add credentials to my password manager. Have you considered adding apple pay support to your shopify account?"
I have no idea if i'm helping or not.
One of the reasons I get lunch from Panera and Pei Wei is because I can check out on my phone as a guest when I order ahead.
Heck, even fleaBay lets you do a guest check out now. That was what made me consider using it again.
Look, I use three email domains for online accounts, in addition to a unique address for each account — one domain that links to my actual identity (my public-facing, professional domain), one domain that’s somewhat anonymous, and one domain reserved for highly sensitive accounts, e.g. online banking, PayPal, AppleID, etc. And PayPal sharing my email address with third parties breaks the model, making my sensitive domain less secure.
i don’t care who processes the payment, i just like being able to buy physical goods without making a new account, and ideally without any more friction than faceID while impulse-buying nonsense while i’m on the toilet :)
Password management is a big problem for non-technical users. Even for people who don’t know/care about security and reuse the same password everywhere, it presents a huge issue when their preferred password doesn’t meet the website’s requirements. They are then forced to make one up which they’ll never remember so it’s gonna be a headache down the line when they need to sign in again.
When they learn that the magic “Sign in with Apple” button allows them to avoid all that, they’ll want it even if they don’t care about privacy.
So far it's only happened once, actually, when Keen.io got bought by a PE firm, I got a bunch of spam, so they clearly sold off my email address.
It's a system that would be hard to operate as a "normal" person, so this is a great step.
My comment meant: "Bye bye " for me. As in: I'm not using it anymore.
I don't get you man.
Mailinator can be pretty hard to use, since so many sites can detect the addresses and block their use.
I've pretty much given up on it, and use Fastmail's very easy aliasing features with my domain. It's not quite as private, but it's a lot more reliable.
The truly clever programmer could open an SMTP session to the mail exchangers specified in your email address, and reject you because they point to mailinator. I know of 0 programmers in the world that have written this code. I think you could ask the vast majority of programmers that work with email addresses and dark patterns to do this, and they wouldn't even know how. So you're probably pretty safe.
I use mailinator all the time and I have never had a problem, however, which is why I don't even have the MX records to host my own anymore.
While I'm sure that works. The main reason I'd use mailinator is for privacy (i.e. not exposing anything associated to me). If I have to use my domain, rather than their free ones, I'm still identifying my domain, so I might as well use my own aliases with my own mail system.
Domains are cheap, and mailinator really ought to register and discard a bunch of $1 specials on a regular basis.
https://account.live.com/names/Manage
(not to take away from this announcement at all; just to provide some context. it's an often overlooked feature which people here might appreciate.)
I also like how you can set it so only a specific email can login. That way if your alias is compromised, your account won’t be.
As someone who changed their name but had to keep their Google account with the old one because of how much Google account data/purchases can't be moved to a new account, this felt positively revolutionary. Google accounts can only have one Gmail address for their entire lifetime.
.
Apple can get way ahead of the competition by combining about 3 things.
1) Ephemeral email addresses
2) OAuth or apples equivalent tokens
3) Keychain autogenerate and auto-populate
If all those products are integrated correctly, this becomes the SINGLE sign on of single sign ons. If a service supports Apple OAuth, your name is hidden, and you only have one Apple password to remember. If the service doesnt support Apple Tokens, then apple fills in a private email address and a random password, and abstracts away the fact that the service doesnt support Apple Tokens. The user experience is nearly the same regardless. Tokens and randomly generated passwords should be managed from the same interface, allowing you to either revoke access (token) or cycle the key (both.)
I've felt it for a while, but the banking industry needs to arrive at something similar. Chase, BoA, WF, and Citi should turn Zelle into a banking OAuth Identity Service.
>For people who lack the expertise or will to roll their own infra then they can use something like Apple ID.
SO 99.9% of the population. It's a nice sentiment, but for what apple is doing to work (random username generation, and identity obfuscation) the only way for it to work is strength in numbers, that the Apple userbase of people who will only use frictionless sign in, becomes too big to ignore, and to tempting too left uncourted.
>It seems like it would be _safer_
Im not sure I would say safer. Depending on millions of people to keep their software up to date hasnt historically worked super well for Windows and Wordpress. One central authority patching all its services and 24/7 devops sounds a lot safer than trusting millions of self hosted OAuth servers to be up to date and not compromised. What percent of people who have non-self-updating home routers, do you think go in regularly and press the update firmware button?
I'm sure there's logging or other AD property (think something like sidHistory[0]) to keep track of this.
Companies don't like being liable for not being able to provide data under order[s].
[0] - https://docs.microsoft.com/en-us/windows/desktop/ADSchema/a-...
In a choice between strictly maintaining your privacy and fines/jail time, most - if not all - companies will sell you down the river (if given a feasible chance that it doesn't entirely ruin them, say for example, if they weren't purely in the privacy trade) to save their own hide[s] (e.g.: see the whole PRISM scandal and its fall-out).
[0] - https://www.reuters.com/article/us-facebook-brazil-idUSKCN0W...