My small revenge on Apple
javierantonsblog.blogspot.com
javierantonsblog.blogspot.com
I agree. I only create accounts for things reluctantly. Because 1. Why do you want my email address, or DOB, or whatever else? I don't want your marketing, and 2. I can't be bothered, I downloaded your app because I have something I want to get done.
Because Apple's SSO will not be eternal and nobody wants to have a tier as a proxy on an important account credential.
Apple SSO is ok for throwaway account where your account has no "sentimental value" that you can't recreate easily. But the author of this post maintains a social network : nobody wants to be locked out a social network.
I have active accounts on websites that existed back when Apple was fighting not to die and I would have totally lost access to them if I had to sign-in to them through my Lycos account.
Don’t use apple SSO because apple might not exist one day?
You may as well argue not signup to anything using gmail because, heck, google might go out of business.
There is no benefit to users in giving your “real” details to service providers; the benefit is entirely on their side.
You can argue that Apple is harming the opportunities for 3rd party developers, sure, taking advantage of them? Sure.
…but let’s not try to frame this as somehow “pro consumer” to give your email away so people can spam you with notifications and offers to lift their engagement rates.
That is pure BS.
I assume OP point is that Apple or Google could still exists but your accounts might not exist, maybe you get banned or just decide you don't want to use Apple/Google/FB anymore.
I don't agree with GP's fear of Apple SSO vanishing without a transition period to something else, but the general premise that this form of login is not eternal but rather short lived in the grand scheme of things is reasonable and doesn't warrant your aggressiveness.
Also you might get locked out of your Apple account for a number of reasons and will then lose access to much more than just Apple services.
I fail to see any problem with this.
There might be a day when Apple is not _my_ cell phone platform. Even now I have an Android phone and iPad and I prefer to have access to same services from both.
I personally avoid to do it, but that's not the point.
Every other third party allows account recovery by mail : if you want to stop using FB or Google's SSO, you can ask the website to send you a mail to prove the account ownership.
If Apple's SSO stopped working (because Apple stopped it, banned you, because you dont have Apple devices anymore so you are locked out of their proprietary 2FA), none of those websites could send you a recovery email.
> That is pure BS.
I don't feel like I've been insulting, so please don't be either.
They have SMS as a fallback. I know it's insecure and I'd rather they support TOTP, but let's not pretend having an Apple device is the only way to receive 2FA codes for your Apple ID.
I pretend nothing, I just didn't knew it since I had an iPhone for years.
This line is unwarranted and in violation of HN rules. Be cool.
I learned something today. I didn’t know you could get SMS codes for Apple 2FA.
Yes. And more to the point, because that Apple service may not exist in the future. Or Apple may determine that a particular app or service can no longer use its service for whatever reason, and you as a user will not have any choice in that manner. It's all been done before.
Given an alternative storyline where Epic Games allowed users to create account with relayed apple mails, wouldn't all those accounts suddenly became unusable today ?
https://appleinsider.com/articles/21/04/20/man-sues-apple-fo...
So has Google, and presumably the other platforms as well.
For every service I’ve built allow the user to create an account with email, Google, Microsoft, Apple, Twitter, Facebook and to later untie their account and move to email. Also if they ever get locked out from their oauth account they can use the email to create a password and login via the normal way.
This is exactly my point ! You can't recover your account if you don't know the mail used for registration. Even if you remembered it, no check could be made if Apple stopped to proxy the mails for one or another reason.
With other providers, you could always recover an account because your email address would let you prove the ownership of the account.
This is the problem with one click account vs email entering. It is a risk users should be made aware of but it is still their choice. And for some critical services I'll use my email, for other like the app in question, or most apps on the App Store I'll use one-click install, also most of the time there is no need for me to have an account. Most data can be stored on device without the need for user authentication.
If they are locked out of the oauth account, presumably they can't check their inbox.
edit: Oh, do you mean you ask for an email address after they already flow through the oauth process - because that's the worst of all :)
I agree that in a perfect world you'd provide your real email address and solve this problem. But developers and companies have repeatedly proven themselves to not be trustworthy and the majority will misuse any contact details for spam which users do not want. In fact there wouldn't be a business case (nor appeal to end-users) for Sign in with Apple if this wasn't a real problem.
They may well offer notice and time when they cancel the service in some future.
They won't offer any of that if they happen to erase your account just because though, as has happened to many people.
https://appleinsider.com/articles/21/04/20/man-sues-apple-fo...
Actually, under that logic it's only that you shouldn't use the @gmail.com domain; it should be fine to use Gmail with your own domain, since that allows you to recover if your Google account is canceled (just change the MX to another email provider).
Another thing you can do is to never use your Google account for anything other than email; that should reduce the chances of the account being canceled for no obvious reason. For instance, it's been reported that, if you used your Google account for Youtube, and Google decided your real name was not your real name (which it wanted due to the Google Plus integration with Youtube), your whole Google account could be canceled; that risk could be avoided by just never logging into Youtube with your Google account.
Right, that's why. Don't ever use "sign in with XXX" for any value of XXX, whether apple or google. Any of them can erase you off their site on a whim and you've lost all unrelated accounts where you made the mistake to "sign in with XXX".
Create accounts with your own email, control your future destiny.
Any website offering SSO options would have a sunset period to move it over if a provider went under...and if they don't, they are likely defunct at that point anyways...
The part where the developer puts the word 'privacy' in scare quotes is a bit of a red flag for me. Suggesting that "accept[ing] two "social logins": Google and Facebook. All was well." does not fill me with confidence that the developer respects privacy concerns.
iMessage backed up on iCloud where Apple has key to decrypt.
>“We specifically don’t collect data, even from point A to point B,” notes Cue. “We collect data — when we do it — in an anonymous fashion, in subsections of the whole, so we couldn’t even say that there is a person that went from point A to point B. We’re collecting the segments of it.
The segments that he is referring to are sliced out of any given person’s navigation session. Neither the beginning or the end of any trip is ever transmitted to Apple. Rotating identifiers, not personal information, are assigned to any data or requests sent to Apple and it augments the “ground truth” data provided by its own mapping vehicles with this “probe data” sent back from iPhones.
https://techcrunch.com/2018/06/29/apple-is-rebuilding-maps-f...
Google Maps:
>Google Maps won't let you save home address without allowing all Google tracking
https://news.ycombinator.com/item?id=18070183
and
>An Associated Press investigation found that many Google services on Android devices and iPhones store your location data even if you’ve used a privacy setting that says it will prevent Google from doing so.
https://apnews.com/article/north-america-science-technology-...
2011: iPhone's Location-Data Collection Can't Be Turned Off - https://www.wired.com/2011/04/iphone-location-opt-out/
"Your iPhone tracks your location for a variety of reasons. It tracks you to calibrate sensors and to improve services, but also to show you ads."
2019: How to stop your iPhone from tracking your location - https://www.cnbc.com/2019/12/19/your-apple-iphone-tracks-whe...
2019: It’s the middle of the night. Do you know who your iPhone is talking to? - https://www.washingtonpost.com/technology/2019/05/28/its-mid...
"The best way to keep something secret is not to capture and store it in the first place. And that’s the crux of the privacy versus convenience debate now redefining our applications and software-based services ... Yes, maybe what happens on an iPhone stays on an iPhone, but some data should not be captured in the first place. Nothing more so than the significant invasiveness of Apple’s significant locations concept—a perfect illustration of just because you can, doesn’t mean you should. This is a continually building data repository of the locations you visit, along with times and dates, detailed maps, even the mode of transport to get you there and how long it took."
2020: Why You Should Stop This ‘Hidden’ Location Tracking On Your iPhone - https://www.forbes.com/sites/zakdoffman/2020/10/04/apple-iph...
“Both iOS and Google Android transmit telemetry, despite the user explicitly opting out of this,” wrote researcher Douglas Leith from Trinity College in Ireland, in a recently published academic report ... “To date, Apple have responded only with silence (we sent three emails to Apple’s director of user privacy, who declined even to acknowledge receipt of an email,” Leith wrote. Since then, Apple has made public statements critical of Leith’s research and insisting privacy and opt-out measures do exist.
2021: Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out - https://threatpost.com/google-apple-track-mobile-opting-out/...
"And there’s also a more fundamental issue with this technology. Its euphemistic description as a “crowdsourced” way to recover lost items belies the reality of how these items are tracked. What you won’t find highlighted in the polished marketing statements is the fact that AirTags can only work by tapping into an Apple-operated surveillance network in which millions of us are unwitting participants."
2021: Remember, Apple AirTags and ‘Find My’ app only work because of a vast, largely covert tracking network - https://theconversation.com/remember-apple-airtags-and-find-...
------
As for "anonymising" user data, Apple has enough data points on its users from various services and sources it collects its user data from to make it meaningless.
There is a lot of profit in collecting and monetising user's data - Apple's shareholder will not allow them to leave it on the table. Apple knows that as it was part of the PRISM program and earned a lot of money by supplying the US government it's users data. (Apple also dropped plan for encrypting backups after FBI complained - https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... ). And on a different note, in the early years, Google too begin it's spying and data collection by convincing its users that it is a "decent" company.
https://appleinsider.com/articles/21/07/02/eu-antitrust-head...
All was well because nobody was forcing me (the developer) to include anything I didn't want. Users could still use traditional email signup. You are free to choose whom you trust. If your choice is Apple, well, that is your choice
In. A. Heartbeat.
You claim (elsewhere) that you only send responsible-sounding emails, but the level of invective in your screed leads me to disbelieve you. Personally, I think HME seems to have been created exactly to cope with people like you - and I’m failing to see this “hype” you talk about.
HME makes the value of an email address tend to zero, gives me the ability to cut you off without your agreement (and prevents you from selling my email on afterwards), and places all the control in my domain not yours. That’s simply the truth of the matter, and it’s not hype.
I don't challenge that Apple ID is a good thing. I protest Apple's method of implementation
I distrust anyone who tries to downplay privacy as important.
I distrust anyone who tries to brand a genuine privacy upgrade as "hype"
And, frankly, signing in (with AppleID or not) doesn't prove a thing one way or another. The OP could be simply harvesting email addresses and selling them off later[+]. (S)he could be upset that HME and SIWA are a threat to that business. Far-fetched ? Sure. More far-fetched than an adult throwing the tantrum on the website ? Not so sure...
Or another option along the same lines. Perhaps OP has another more-public site that (s)he doesn't want to take this stand on for PR reasons, so they're doing it here, and getting "awareness" out there by submitting to places like HN. In that case, sure, there'd be no email abuse on the <don't care about> site...
There's a few other options that are possible. None of these get around the basic premise that privacy on the net is important (at least to me, YMMV) and I don't trust those who decry it.
[+] Tesla does this, for example. All of a sudden, a couple of years after buying power walls, I'm getting emails to Tesla@<my-domain> and texts containing Tesla@<my-domain> to my phone number (which I usually obscure using google-voice) asking if they can give me mortgage offers (for example). Tesla sold my details when I stopped buying expensive stuff from them - this is why I set up a catch-all address, and used <company>@<my-domain> whenever I signed up for stuff. Now I use HME.
They don't seem to be able to grasp that maybe there are different viewpoints in this world. Maybe that's even a good thing, and perhaps denigrating entire swathes of people as "fanboiz" says more about the person doing it than about the people they're complaining about.
Just maybe.
You mean like you're doing?
Kettle, meet Pot.
I particularly like this Apple fanboi argument - that having a third party (Apple) needlessly involved is somehow more "private" than only just the 2 primary parties being involved.
>I'm a Brit
Well I guess that explains a lot then - you're probably one of those that also voted for brexit, but now completely denies it - right?
Maybe you're a good developer. And? How many sites on the internet do you think I'll have to trust before it backfires?
> I protest Apple's method of implementation
How else could it have been implemented that would have led to any reasonable adoption rate?
Offering Apple as a choice does not remove the customer's ability to use the two biggest names in surveillance capitalism as the "protector" of their privacy.
Being this angry at having to give users the option of better privacy really isn't a great look.
Which used to offer both social sign-up (FB and Google) and a traditional email sign-up option
You probably don't know that in this case, Groups was also forced to include AppleID or risk being removed from the App Store
Removing all social logins from this point to ensure compliance would have definitely affected all users who had originally signed in with FB/Google, way before AppleID ever existed
Yet it would have been more consistent! What is the point of going to war against Apple while embracing the private-data-broker model at the same time?
Just send a warning e-mail requiring password change because you decided to remove all social login as a protest.
And provide a password reset mechanism for formerly social-login users that haven't defined a password in time.
That would have been a true act of resistance.
Apple decided to prioritise users over developers here.
As a user, I am very satisfied that Apple made this a requirement.
As a developer, I just implemented it without throwing a tantrum.
1 - Activation email with activation code to ensure the person actually owns the email address (non-OAUTH sign-up)
2 - Password recovery for when they have forgotten their password. Yes, a user doesn't need this with OAUTH but sometimes they will have forgotten that they used OAUTH to start with and need to sign in with email & pss
3 - When push is turned off and someone has messaged you
I don't think this is beyond reasonable but I'm willing to take criticism
And I think Apple's behavior should change so I am making this public
Because this response tells me you’re willing to compromise your user’s experience because of your personal issues with Apple.
As a user, this does not give me confidence in your decision making.
It’s somewhat understandable to be annoyed, even angry at Apple. But the moment you decide to pass that on to your users is the moment you’ve forgotten the most important humans in this story.
Of course, it’s your right to do what you want, and if that means taking a stance against Apple ranks higher than your user base, I suppose that’s your prerogative.
But that definitely would make me hesitate to use the app.
I don't even hold a grudge against Apple. This is just me trying to make the world a better place. It's in everyone's interest that Apple doesn't gain authority to force us to do things (don't forget, devs also are Apple customers)
On the other hand, I absolutely trust Apple - my relationship with them spans over a decade and countless products/experiences.
I’m happy that they’re forcing devs to offer Apple Sign On as an option when other social logins are also offered. As a user, I trust Apple far more than any 3rd party dev.
I pay a premium to Apple because of their platform and the types of things they enforce.
I want you to understand that as a user, this is exactly what I want Apple to do and I pay extra for it.
This reads like "I know what's best, despite what Apple users say they want, and I'm going to make the world a better place by ignoring my users and telling them what they want is actually bad for them", despite the fact that this is actually a beneficial feature to users, even if it could be construed as a benefit to Apple as well (arguments can certainly be made).
> It's in everyone's interest that Apple doesn't gain authority to force us to do things
The rulebook to participate in this ecosystem is a mile thick. Why is this the issue that you choose to make a fuss over? There are a a myriad of other rules that are even more heavy handed, that actually are to the detriment of end users to protect Apple's walled-garden.
Picking a feature that arguably makes user's lives better seems tone deaf at best, and actively harmful to a broader message about openness at worst.
Petulance does not become a developer. The last time I saw a tantrum thrown this much was when my kid was 5 and had a major meltdown over a lack of chocolate ice-cream.
He didn't get any ice-cream for a week, a response that taught him meltdowns don't work.
Now I ask you this: how far are you willing to go to further a good cause? Watching from the sides feels more comfortable, but we are being decimated and doing nothing won't change a thing. We need to act now, or watch our profession/hobby/passion be used to fatten the already morbidly overweight big tech companies
But what, exactly is the "good cause" here? Is the good cause to force Apple to stop delivering an experience that we've already established throughout this thread is an experience Apple users want?
There are so many problems and battles to be fought in tech, so much abusive behavior, so many dark patterns. This is not that. If this is the cause you're fighting, I fear you've missed the forest through the trees.
Unless you had something else in mind, in which case I'm genuinely curious.
Enslaving the entire Uber driver or deliveroo poor sod population is arguably beneficial for users. But, is it right? Plenty of jurisdictions have already spoken that these workers have rights. Nobody has made a ruling regarding developers yet
The "iMentality" can't possibly extend to wishing that Apple treats other human beings like **. Can it? If so, we may have gone back in time to even before the 1860s
hobgoblin33@ussr.ru doesn't carry much info.
Just googling someone's email is a start. But worse actors can find your email on a combolist or figure out what other services you use. Just knowing someone's email is the first step to social engineering a customer service backdoor, for example.
AppleID specifically helps users avoid all this with trivial per-app email address generation, and that's something our tools should have given us a decade ago.
I don't care. I don't trust you. I don't trust any of modern devs, I see every other new shiny crap on the internet only as an attempt to extort me of data and/or money (subscription) now. Before Apple introduced that feature I was using email aliases in my Fastmail. Need to register in new service - go to Fastmail, generate an alias for some weird domain they've got, setup filter for it to go to "dodgy" folder and then register.
Now I don't need to do that anymore, Apple automated that for me.
And thank's Apple it also forced guys like you to allow me to use that automation. At least on their platform.
For same reason the only way I buy a subscription is through an in-app-purchase - because I can just to go App Store and cancel it and don't need to deal with people like you. I remember like an year ago I was waiting for a refund for a cancelled subscription and my emails were ignored and the only way to get the attention was to open a dispute in PayPal. Yet another supplier-hostile but consumer-friendly company. Thanks god they exist.
Apple could be considered a genuine neutral arbitrator if it didn't take money from both the developers and its users. What it has done instead is to force itself between the user and the developer, and exploiting both in the name of the users (developers lose money to Apple's extortion, and the money it extorts from the developers is ultimately passed to the user, and thus they end up exploited too).
And even if they do, too many developers couldn't give two shits. Great example is how users overwhelmingly opt-out of tracking when the OS warns them about it (because "developers thinking about users" never even considered not tracking)
Like minded developers are not just fighting Apple, but the whole attempt by "big tech" to move to the business model of exploiting developers by controlling distribution of softwares, and dictating terms that favour them. This ends up harming both developers, as they earn less, and users, as ultimately it the user who ends up paying the share of profits that Apple (and others) extort from the developers.
I wonder what it would take to "force" me into doing a social login? It would have to be something drastic, like a website that provides me with needed oxygen.
To get on my hobbyhorse some: what about a platform that your employer uses to distribute relevant documents and updates which you need for your job, which has become sufficiently well-known and implicitly available that hesitating about the dependency is perceived as bizarre?
Note that the response of “don't deal with them then” runs into market information and churn amplification¹ issues when it is a social assumption that picking up a ‘tool’ (which is actually a relationship with a third party, but where this is close to invisible in the steady state) is essentially a free action which requires no consideration, because the information about “does this employer require me to use this tool” neither propagates efficiently nor stays stable.
Past source: wound up changing the email address on one of my Google accounts recently for exactly that reason. They actually asked me up-front whether I had a GMail account they could use instead, which turned out to be because they use restricted Google Docs for critical material. Not naming them, but in a broad sense, this is one of the more ethical companies I've ever dealt with, by the way.
Future source: I should probably be considering digging into LinkedIn soon despite their past abusive behaviors, because as it turns out, if I want to dig myself out of this hole…
¹ I assume there's a ‘real’ term for what I'm thinking of, but I don't know what it is, so I cobbled that one together out of the most relevant-seeming bits.
Apple has never shown me hostility. On the contrary, I found Apple to offer reasons why they do things and how to work around them. Have they sometimes forced me to do things I don't want (and felt were worse)? Yes. But it was obvious what I needed to do to comply.
Restrictive is not the appropriate word.
For example, this whole forcing devs to use "sign in with Apple" is not about imposing restrictions as you can decide to not use a third party sign in (on a new app).
Apple is saying "hey if your users can sign in with Facebook they should be able to sign in with Apple, we want a piece of the pie". Some iOS users are happy about the privacy aspect of this but fundamentally (IMO) this is not about privacy or restrictions, it's about making users and devs more dependent on the Apple ecosystem.
If they made it optional, a large percentage of apps would force you to use Google/FB to login. That's not acceptable to me.
One of the major reasons I give Apple money is to because they can stand up against the privacy invading FB/Google and I, as an individual, cannot. So they are very much doing what I want in this instance.
It's explained in my previous comment.
Not well enough for me to understand, because I asked what you meant.
Apple does the same thing. As a dev once you open the door to using Apple you're forever stuck with that. As a user, it entrenches you further into the Apple ecosystem which is ultimately the whole Apple product strategy.
I like this result as a user.
I have to be honest here and say that I amazed, but sadly not surprised by the level of entitlement on display from a very small but extremely vocal set of developers.
My behavior? You have no idea what I do. I don't even develop for Apple platforms.
> Why should your user have to use an anti-privacy 3rd party like Facebook to use your app or service?
I would never use anything by Facebook. Not sure where you got that from.
> Where is the users choice other than to not use your product?
That is choice.
> I amazed, but sadly not surprised by the level of entitlement on display from a very small but extremely vocal set of developers
As a dev shouldn't I be able to have control over my application?
But I wouldn't want any of those companies know which services I use. I am fine with using Auth0 or other third party providers, but only if I have to.
You don't even need to verify the mail in my cases, you could even use a completely fictious one. Clean, easy, anonymous.
Not really sure about smartphone hell, but most identity providers offer up the mail of the user anyway. Maybe that is different in phoneland though.
I used to prioritize the domain's own login, but now I'm starting to mix in some logins with Apple... I just prefer to have _less_ people have my personally identifiable information.
I run my own mail server so it's easy for me to implement vendor-specific email addresses that cannot be correlated with other vendors', but more and more companies are offering that as a service nowadays, DuckDuckGo most recently:
https://www.spreadprivacy.com/introducing-email-protection-b...
I do use GitHub federated login, but only for apps like vulnerability scanners that do need OAuth access to my repos.
Neither is a good thing
If I were to write an iOS app, I likely wouldn’t. I don’t trust myself handling that kind of thing securely.
You don't get anything beyond what you ask for AND are granted access to by the user.
FB login gives email and name AFAIK, but you can ask for lots of other stuff and be denied. Google defaults to email, not sure about name, and has separate requests and grants for any additional information. They don't have nearly as much of a profile as FB does, but can give address and some other details. Apparently Apple doesn't even provide a real email, so that seems even better for "collecting [your] personal information" than using... your personal email address!
Social login is much better than storing passwords in any form (plaintext, encrypted, hashed), and gives both the user and site owner the benefit of FAANG security.
Users want
- Easy access
- A familiar experience
- A consistent experience
- To avoid more passwords
They generally are not aware of the privacy tradeoffs they're making by using social login.
I'd argue that if the developer truly wants to fight the good fight, they should remove social login altogether.
I find it odd that the options they support willingly are the options that are most user-hostile from a privacy perspective while the option they begrudgingly support (while making a big fuss about it) is the one option that actually tries to protect the user.
I'm really annoyed Vercel stopped offering email signups.
But the bit I highlight is a nice jab at Apple and something I think you can get away with professionally in a web app. It mars their login brand a bit by showing that it isn't useful everywhere.
Apple is making it impossible to have real customers and real businesses. They're turning us into serfs of their unfair ecosystem.
It's one thing to build interconnected products, but to grow the pie so large that all commerce and communication with 50% of Americans goes through their polished gates, to be stripped, taxed, and even cloned, is an abuse of power and position. It's a strip mining of our industry. An over fishing that has greatly decreased the probability of success for small, independent players.
Until the DOJ forces them to open up (or break up), we're stuck in this war zone.
I'm going to follow in your footsteps. Hopefully many more do as well.
I keep regular correspondence with many of my iOS users and I consider them to be my friends. They've helped me shape Groups' current form in many ways. I am thankful
Except it's inaccurate, it works on Android, Windows and in browsers https://support.apple.com/kb/HT211687
Agreed on all other points though, if you want to garner sympathy from your users, that's definitely not how to do it.
I'm pretty sure there is an implied "on this app" in there. But I agree that the formulation could be seen as ambiguous.
It's one thing to argue against the policy and there's nothing wrong with that. But it's unacceptable and close to outright lying to imply that the policy decision makes the user's account only usable with Apple devices.
The really puzzling thing about all of this is that the developer's primary issue - he believes Apple is being hostile to developers - is exactly what he's doing to his end users.
Apple took away his choice, so he's taking away his users' choice to use the feature as they desire.
And it doesn't hurt Apple in the slightest, couldn't agree more.
"Sorry, we're only able to support Apple ID on Apple devices at this time."
At the end of the day Groups is a passion project. So it can be used to contribute to a world where developers aren't taken for granted
Apple ID was buggy as hell when it first came out.
Apple users will have to understand that Apple's policies can have an impact in what they get from developers. Apple only cares about $ and PR, wish it weren't this way
I think apple cares about their users and platform, they just care about your passion project and I can understand how that triggers you. But the users belong to the apple ecosystem. You are essentially a guest there and more importantly the user has a choice to privacy. Most of my friends buy iPhone because of ApplePay, Sign in, and now throwaway emails. Apple just caters to them and forces all developers to respect that.
As an engineer I never experienced any issues when integrating with Sign in. I’ve used it in 3 apps already in the past 2 years. There was also a very long grace period.
More like a prisoner, rather. As an Apple user, I would like to be treated as the owner of a device I have paid for - not like a "guest" or as a "prisoner".
GP was referring to developers as guests, I believe, not to users.
But please tell me, how else can I push back on Apple's bad behavior? In war, there are collateral victims. And I, a dude who's almost a nobody, is willing to take on Apple by any means necessary when they do this kind of stuff
Respect is earned, and it is high time Apple learns to respect developers. We should all be doing this kind of thing. I'd go as far as supporting a general app strike where services become unavailable. That's pretty much how workers have gained any rights and we desperately need rights
Please review what "war" means, also.
Users own their Apple devices, Apple does NOT own it's users.
As for Apple owning the user - elaborate pls. I don't see how they try to even own me. I made an educated decision to use that software and hardware BECAUSE of things like ApplePay, SignIn, App Store, etc.
<<apple cares about their users and platform>>
You have to clear your mind, the don't care about you, they care about your money only. This is why they want you to be captive but they pretend that it is for your own good. And you buy it...
I understand being a developer who does a passion project or an app. But I can't buy into, Apple forcing any developer to make a decision in a very short term. Almost all new guidelines comes with a 3 months interval before being enforced. And most times the deadlines get extended https://developer.apple.com/news/?id=03262020b
Apple waits a year or more before removing the Apps that don't follow a newly enforced guideline. The restriction is a problem with app submissions that comes in after a deadline
Will avoid.
> Perhaps Apple customers deserve the luxury of "choice" (between different Apple devices, of course)
I don't understand the tone. Do these people actually not understand that different people have different preferences and priorities? Or is it a pose of some kind? I mean, it's 2021, Apple has been on fire pretty much continuously since 2007, they're making a killing everywhere they go and they're, as we speak, pulling off the biggest and smoothest on-the-fly architecture transition ever.
Is it still not clear to some people that Apple users genuinely enjoy using Apple devices and that the company clearly does something right?
What are the options in the smartphone landscape? Please elaborate in a way that my elderly mother could use without 24h tech support from family members.
Android? And have instead of golden handcuffs a straight-out chain to serve the ads landlord? Yeah there's only a "choice" between the comfortable golden cuff of Apple and the being actively exploited by google. I know what to choose.
Obs. For anyone suggesting giving a de-googled lineage phone to my mother, just, please, don't.
ftfy. I get a bit fed up with seeing these things promoted. I’m from New Zealand, not the US or Europe. Where do I get one? Who fixes it when it buggers up? Why does it cost so dang much? Why is it such a slow piece of crap compared to my iPhone 11? etc.
To me Apple stopped being on fire for a while now, in particular as we switched from broken keyboard laptops to wonderful ARM laptops only available in small sizes with 2 usb ports. Also on principle Apple barring third party browser engines and game streaming are two huge no-go, in continuation to the selective ban on interpreted code which almost kills the editor ecosystem. Those handcuffs are not that golden, really.
How so?
I think I could easily pull all my data out. Files are, well, files; contacts and calendars can be exported in standard formats; photos are stored as JPEG or raw; music is MPEG-4; e-books are epubs; whatever.
Sure, I'll lose some features, but that's because other platforms don't offer those features, not because Apple is heinously putting extra effort into locking up my data.
Are you sure ? I don’t use iBook but it doesn’t look to me like you can just export them as e-pubs and be done with it: https://www.igeeksblog.com/how-to-export-ibooks-from-iphone-...
- Try to export your photos from Google Photos
- Try to export you photos from Apple Photos
Let us compare those two, shall we?
Google Photos:
- stored in cloud
- no _synchronisation option_
- export exists but you loose metadata unless if you do it through API so third-party sync is not possible as well
Options to get your data back:
- Manually select all the photos in web ui and click download.
- Use google takeout option.
Apple Photos:
- Synchronisation. Go to settings and click checkbox "download everything to this Mac". Same for iPhone. Offline ready, your data is on your device.
- Export - just go menu and click "Export originals". It will conveniently organise your photos into files and folders. No internet connection required because the data _is already on your computer under your control_.
So, to answer your question. If Apple stops being on fire, I export my data in a single click and move it somewhere else if there's any option. But it will be sad day because I'm afraid that there will be no option, besides Apple the market is filled with liquid shit that treats users as cattle.
P.S. The example of photos works for everything else - my music library is synchronised and downloaded locally on multiple machines. If you've got Apple Music subscription you can drop anything in there and it'll upload it. Basically dropbox with UI of iTunes and Spotify on a side.
Same for iCloud Drive - it is downloaded locally. Heck, everything is downloaded locally, stored on my Macs and backed up with time machine. My data is under _my_ control when I go with Apple.
If they didn’t force developers to adopt this, they would never do it as it’s in their interest to harvest the e-mail addresses of their customers.
So anybody who is using Sign In with Apple trusts Apple to do the right thing.
Besides, what monopoly? Apple is perfectly happy with other single sign ons — provided you also offer Sign In With Apple.
It is pretty standard "embrace, extend, and extinguish" strategy. Similar to what's happening in the browser market. They are waiting for majority of the apps to have their sign on and majority of users use Apple sign on, then update the policy to disallow other methods.
I mean I don't have any issue of Apple doing these in their own ecosystem, but at least don't be so hypocritical or naive when defending them.
If the only other options you provide are Google or Facebook, you (as an app developer) clearly doesn’t care that much about privacy.
Apparently Apple doesn’t feel that any other providers care enough. That’s why they’re mandating the use of their privacy-focused solution.
They are using their app store monopoly to gain a foothold in the single sign-on business. You could try to claim that there's no business there but look at how Microsoft got spanked for giving away a free browser. Now the Apple has over half the phones in the United States, I'm looking forward to them getting spanked very soon hopefully.
Yeah, it's practically the same thing if you just ignore the basic facts of the case.
That's exactly the kind of behavior that Apple is exhibiting here.
It's pretty easy to come along and say that I'm "ignoring the basic facts of the case" though without presenting any facts of your own to back that up. So let's hear your take now.
[0] https://en.wikipedia.org/wiki/United_States_v._Microsoft_Cor....
But again, Sign In with Apple sits in addition to the other offerings, it doesn’t replace them, and in no case are developers expected to be unable to offer regular sign in with email.
To my mind, you’re not wrong, but making a rather different argument.
They don't, and aren't trying to. They are trying to disrupt the Google/Facebook duopoly in the SSO space. Devs are free to require new accounts that they have the email for, just not outsource it to FB/Google.
the rule seems somewhat orthogonal to developers getting emails. Developers can still request login by the old school email-and-password with (or without) sign-up verification by email. On the other hand, some third-party logins don't give developers their users' contact information (just a token to verify that they're on their platform with no authentication permissions, or a dev can request that this be so else the third-party will inform the user that the dev is requesting their contact info).
The problem is not the social sign in aspect, but that fact Apple forces you to implement it if you use their competitors' service.
Had Sign in with Apple not been mandatory, but merely something customers would ask developers for, then I'd consider the framework to be fair game. This simply isn't that.
That's interesting, I would have said that it was AWS doing that with Graviton. Do you have a source for this?
I think Microsoft's architecture transitions between OSes were far smoother, in terms of ensuring backwards compatibility and giving developers far more advance notice. Of course, they stayed within the same chip family (well, except increasing the N in N-bit), so it was a smaller transition, but it worked well.
And of course, it's terrible Apple doesn't allow their login button image to be altered so that an average user could quickly identify it as "oh yes, this is Apple". However, I don't see why this could be not good. Also, as an end-user, I don't care if the Apple button is black, the Facebook button is blue, etc.
It seems it's always the others who are wrong (see this: https://javierantonsblog.blogspot.com/2021/07/my-app-just-go...).
I'm not so sure about the app. From these two posts alone, I wouldn't trust this app.
The fact is, I send 0 emails and privacy and security are top priorities. I am passionate about E2E encryption so I have integrated loads of that in the app too
The only purpose an email address serves is password recovery. Period
TBH I am a bit tired of people trusting big tech so much. They are businesses, meant to make money. I make no money and don't intend to cash out because I am passionate about what I do. It's so frustrating to see how people blindly favor big tech
- "privacy and security are top priorities".
and then
- Wants to force users to only use the least private log ins: via Facebook and Google
- Is pissed when privacy-conscious users hide their emails via Sign-in with Apple
> I am a bit tired of people trusting big tech so much. They are businesses, meant to make money.
Yes, yes they are. So why do you trust FB and Google and force your users to use those log in methods?
I don't force users to use Google/FB. They can use traditional email signup just fine
Emails could be masked before Apple ID came along. Namely, gmail addresses let you do this. So it's not anything new or revolutionary. Users could use that to sign up for Groups before
I would have probably ended up implementing Apple ID, but the fact that they forced it in a most discorteous manner frankly p**d me off. When someone does this kind of stuff you need to remember and try to curb their behavior where possible. That's what I'm doing
ps. I don't trust FB or Google either
How? I've used gmail for over a decade now, and I have no idea how to do that with my address.
> I don't trust FB or Google either
And yet you have no qualms providing a login through either of them both in the app and on the web.
So much for "I care about security and privacy".
It's not nothing (I tend to use it to track how my email address is being sold), but not a real level of masking, since anyone in the know could regenerate the "standard" address easily.
And you can still do that with Apple's email relay. So I fail to see where's the problem.
However… when looking at apps and signing up for them, can you tell me how I would differentiate someone like you (who I can probably trust) with someone who will sell my information, or send me a ton of emails?
Even with good developers, some will make mistakes and lose data. Some will get sold and the new owner will do different things. As a user, not only can I not pick out the bad from the good, but I don’t know that the good will be good forever.
(I say this as someone who has been burned a few time. Always using a different email address when signing up allows me to track who is doing bad things. It happens far too often)
Of course it is easier when you can relate the app to a physical person (as in my case). How can you make sure the physical person has good morals? That is a lot harder
I did dislike implementing AppleID purely because I was told to do it and even how to make it look which went against the design I'd already nailed for the app. It just put me off. I just wish Apple treated developers with more respect but it seems even Apple users are happy that they mistreat us. It seems Apple users enjoy the "power" Apple has over us. I think that this is just evil. It's like enjoying the "power" Uber has over the taxi market, or the "power" Deliveroo has over the miserable sods that do the deliveries. I don't know what the solution is, but Apple needs to change this behavior and the only way might be to "convince" their users somehow. Strikes are never a pretty sight
Again, I guess you could draw an analogy with Uber. We used to depend on our luck to find a clean/respectful/honest taxi driver and now we rely on Uber to manage this for us (with reviews etc). But Uber never really had their drivers in mind, and it took collective action for Uber to start respecting them a bit. I think that something similar needs to happen in the app space. We need rights
"It seems Apple users enjoy the "power" Apple has over us." --> Absolutely yes. But it just goes back to my main point - I am unable to vet app developers. And even if I do, there is no way to ensure data is handled well long-term. What if Facebook makes you an offer you can't resist?
Basically, I have had many experiences with developers abusing my information. Now I have someone fighting back for me (don't get me wrong, I'm not an idiot. I know they are doing it because I pay them an obscene amount of money).
The way to convince people is for developers, as a whole, to behave responsibly. If developers had never abused my information, I'd likely have no issues ever giving them some of my information.
Edit: I'd just like to say again that I am in no way saying that you are doing anything bad. You seem like a good fellow. And perhaps the curse of being one of the few good people in a room of bad people.
I had a quick look at your app's e2ee and summarized my findings here: https://telegra.ph/Reviewing-the-app-behind-My-small-revenge...
Feel free to correct.
First of all, thank you for taking your time to do this. I still wish you'd told me before so that I could help you understand a few points before publishing, but I totally get it, good effort. A bit unfortunate that your post got flagged and taken down
A few comments:
> chat keys are ever changed or when (forward secrecy)
Yes, this can be done anytime by any user. Chats -> Settings -> Renew RSA Keys
The Windows client doesn't include any chat capability, it's not just that it isn't E2EE, you simply can't send/receive messages on it. I plan on replacing the Windows client entirely with a web version, it's only there for some few users who really need it
>it's legal to have a directory of all registered users and email addresses accessible to all users
This is not the case. Users can only see other people's contact details when they are in the same "Group". Otherwise, both email address and name is hidden
>On Android, the standard `Random` is not entirely[5] based on current system time, but it does not seem like Codename One uses that. The documentation says it's purely time-based.
I think you may have missed that every message is encrypted with the ChatKey but also with a different IV each time. This ensures each message originates from a different seed
Don't know if you can update your post with this info? Anyway, thanks again and happy to discuss! I might have missed some points. Tbh the E2EE chat isn't really used by loads of people and in retrospective I should have made it non-E2E since most users use the app for its organigrams and not for secure comms. I just did it this way for fun
Edit: One last note
>If you're going to use a closed-source E2EE chat application, you might as well use WhatsApp
The problem with Whatsapp is backups. They kind of make E2E pointless
Edit 2: feel free to reply directly to javierantonf@hotmail.com I can't guarantee I will see your msg here
Edit 3: Isn't 2048 valid until 2023 and possibly beyond?
Finally, I am happy to let you have a peek at the source code if you want to know more about it. I want to OS it but can't get around my paranoia of doing so. You'd just have to make your identity known and offer an email address or similar
The author seems a little in need of therapy and to walk away from this for a little while with just how angry, sarcastic, and tonedeaf it all reads and to be clear, I'm in therapy, it's great and helps.
Honestly, I don't know why he is offering social login on an app that advertises E2E chat anyways, you are just giving them all the Keys to the Kingdom.
Privacy-preserving federated login options are a good thing. Knowing that the app, which may or may not have security or data protection, has less access to my information is good. I don't necessarily like Facebook, Google, or Apple having access to my information, but if they're the only ones, it's still better than having the app developer have it. Moreover, Apple's login is presented to the user as a user-positive feature: I can obfuscate my personal information conveniently. I like that.
If an app didn't have federated login, I'd make a judgment call about whether or not I want to create an account. Maybe I would, maybe I wouldn't. But if it does have a federated login option, I'd like them to support a variety of options, including Apple.
I'm not sure Apple should mandate it in the way they do, I can appreciate that the developer feels strongarmed... in the same way that I'm sure credit card processors engage in shady strongarming behavior of retailers. But I'd still rather go to stores that take credit in addition to (or instead of) cash, and I don't find it noble that the developer is writing that being forced to do something that his users would benefit from is bad for him.
I then read the second post the author wrote about getting his app removed from the Play store for not including a link to the privacy policy and it kinda comes off the same way. I don't necessarily like Google arbitrarily removing stuff with no notice, but I do like that Google has decided that a privacy policy should be a requirement of an app, and I sort of resent the guy complaining that he shouldn't have to follow that rule, which benefits me. He characterizes this as a "bad experience for users". I don't really agree.
I really like the idea that an SSO can also server as the single point of trust for personal information like an email address. I just wish Apple let that feature speak for itself. I wish they put in the effort to make Apple ID a popular auth solution because both devs and users actually want it - not because they're forced to have it.
Like us. We have Facebook sign in (appropriate for our market), but couldn't integrate Sign in with Apple because the email private relay limits how you can send email to it so much, and we use the email address as a fraud signal for some payment providers.
It comes down to the fact that we share email addresses and Apple have stopped that from working. They see it as stopping advertising and spam, but in our case they're preventing certain payment options, delivery notifications, refund notifications, all the sorts of emails that users tell us again and again are very important to them. We're not sharing emails without consent, we're doing it where users know what's being shared and why, and want these features.
Edit: I wrote up a bunch of these issues at the time it was launched: https://danpalmer.me/2019-07-02-on-signing-in-with-apple/
If they do not share your email, that means they do not actually value your emails as much as you seem to think.
I might believe your intentions are noble, but for one of you there are hundreds if not thousands of bad apples, so to speak, and the controls Apple is giving me as the user help mitigate it somewhat. And there are initially good apples that turn bad after a while — as their authors are desperately seeking ways to get into black, or just sell their apps to some unscrupulous businesses.
Or am I missing something?
This is not in the interest of the user. As a user I do not want yet another company getting my details and assembling a profile on me under the excuse of fraud prevention, especially when my bank offers 3D-Secure which shifts all fraud liability back to the bank.
> all the sorts of emails that users tell us again and again are very important to them
According to every company every single one of their spams is important. It's not up to you to decide. If the users want your notifications they will find a way to receive them (as far as I know the Apple relay email address does just forward emails, so unless you're breaking a - presumably reasonable - rate limit it shouldn't be a problem).
This is only done after an explicit opt-in when using just that payment method. It's actually done as part of a credit check and those have to be very explicit.
- Do users understand the fact that they have not given us their email address? Our email turns up in their inbox after all. Our customers are not necessarily tech-savvy of even that comfortable with email.
- Do users know, months after signing up, that they didn't give us their email address.
- Many users don't actually read information longer than ~5 words unless they're seeking out FAQs or something. They mostly pattern-match to things they know and/or expect.
- Interrupting a checkout flow to explain all of this and capture a real email address will significantly reduce conversion. Is it overall better accounting for the hopeful improvement from Sign in with Apple? Very hard to say, even with testing, and we've tested things like this in the past.
- Will Apple allow it? Open question, they don't explicitly say either way but there's plenty of evidence to suggest they don't want it being done.
> This is not difficult unless you want to make it so for the purpose of raging at apple
There's a difference between raging and critique. I'm critical of what I see as poorly designed systems and policies, particularly where it seems like there are industries/business models that are blind spots to Apple, intentional or otherwise.
Saying that I'm raging at Apple is funny to me because I lead our project to introduce an iOS app at my current company, I've worked at an indie Mac software company, I have used macOS for many years. Hell, I even liked Objective-C. In many ways I'm just yet another Apple fanboy.
Constructive criticism is important in moving platforms forward. Right now, Apple SSO doesn't work for us for well defined UX and business reasons. If those are solved then it will likely align well with how we want to treat our users and we'll likely introduce it.
I'm sorry, I understand that that is not your point, but an email address is a terrible fraud signal.
Also, if anything having the email go through an Apple relay, means that the user have an iCloud account, which seem no more risky that a random Gmail account.
In my case it was just a nickname, but using an email as fraud signal also feeds into racism. People who don't have an average white American-looking name will suddenly be flagged for fraud.
Edit: being super clear...
The payment method is a pay-later service, it's literally a loan. The email is used to look up to see if the person has paid their loan balances off late before and other factors like that. "Fraud" was probably the wrong term to use here.
So in the headline you call it "revenge on Apple". Apple is hurting, supposedly.
In the content you say the above thing. You're hurting supposedly.
The only option that's missing is the correct one. You're not hurting Apple, and you're not hurting yourself. You're hurting your users.
As an iPhone/Mac user, we don't need developers who lead these confusing, petty ideological battles with Apple at our expense.
Wanna win your tiny, tiny "war"? Good, remove your app from the AppStore, we need less garbage in there, and if Apple did their job right they'd have done this for you already.
So, help me understand here -- the revenge is punishing their users that signed up with Apple ID? In what way is this revenge against Apple?
While I firmly believe anyone's data can be breached, and Apple ain't no exception, it's more likely for a Joe Random Developer to make his unauthenticated document-based database listen on a public IP address than Apple. I say that even taking into account my firm opinion that Apple is very inept at clouds among their peers, evidenced by the atrocious quality of practically all their network-based offerings.
> But Apple developers must be told, threatened, shut down if necessary.
All developers, not only Apple's! At least Apple has some leverage over its paying developers. I wish it started harassing them over unreasonable memory/CPU usage too, but it's hard to do if your own platform is guilty as charged.
> Am I hurting myself? Am I shooting myself in the foot? Probably. But this is war
Petty and reminds me of scaring a hedgehog with a naked butt.
It’s kinda depressing that there isn’t more choice and competition in the mobile space. Your choices are Android and apple.
RIP Windows Phone, WebOS, Meego, Firefox OS, et al
It just targets devices your probably don't want to use (as in with physical buttons), so you haven't heard of it.
The amount of utter shit in the WP store was astounding. It was like if every single 0 star GitHub project had been submitted to a store for everyone to download.
He was very happy with it, then it was EOL-ed and WhatsApp stopped working on it (I consider that a feature, not a bug, but for some odd reason he disagrees). So I set him up with a LineageOS Pocophone F1. He still misses the simplicity of the Windows Phone UI, though.
The Metro/Modern/Whatever UI looked good in screen shots. In actual use the tiles just ate up a lot of screen real estate and rarely refreshed their content when expected. The UI inside apps was equally brain dead with touch elements often lacking borders. So you'd have to hope you aimed your finger perfectly on an icon. Because the UI could become unresponsive for unexpected reasons, especially on garbage phones, even if you hit an element it wasn't clear if the app was actually responding.
Windows Phone 8 and up was a dumpster fire. The highest end phones were just okay and didn't really hold a candle to the Apple and Android flagships of the time.
Release a phone platform. Then another, incompatible phone platform that looks and behaves practically identically.
Reminds me of Windows 11. Three different kinds of control panel, two different kinds of context menu, infinite different kinds of window frame.
MS competes with itself!
The rest of your comment, I sadly agree with.
They were also baffled that I wanted more than 5 digits as login PIN (without username) for the banking app.
But yes, Apple is great. Again, Apple is great. Apple good, good good good
To this date. Tomorrow, though, no one knows.
> I have sent 0 marketing emails trying to sell stuff.
"I", "I", "I". It's not you. It's me. I don't care what you say you're going to do with it. I don't want to give you my email address to store in another database. I'm sure you're very nice, but sorry not sorry.
> The only reason email is needed is for password recovery
You don't need my email at all if I can use Apple ID.
The fourth sentence on the page says "sending personalized emails" as if it's no big deal. I don't care what you think the purpose or value of your emails is. I don't want emails from any app unless it's a support response to an email I sent first.
I do need them for everyone else who comes from traditional signup
However, you seem to have missed the point. My problem is not AppleID, my problem is that Apple forced it on my app and threatened to shut me down if I didn't include it
They want you to redesign your app so that you don’t rely more n mail to provide functionality. It’s a good thing, even for you.
I am an Apple customer as much as an iPhone user is. But Apple chooses to treat me as an employee, after having charged me (and paid me nothing). Do I have the right to be upset? Could they not have sweetened AppleID by encouraging users to ask devs to implement it or even by reducing our dev annual fee by some $? I think it would also have worked
1 dev subscription 4 iPhones to test 2 iPads to test 2 macs to develop
Why do you get to "expect" things from me, and why does Apple get to force me to serve you in a certain way that keeps changing over time and then threatens to hide my work if I don't comply?
I don't know, it just doesn't seem fair. I am happy to work for free because I like what I do, but then being told to do things or risk being banned is just too much for my taste
I think I will just leave the App Store when my web version is finished. Too much trouble for nothing
The average apple customer values consistency and is far less tolerant of deviations from that than the average microsoft or google customer. The whole point in paying more for apple is because we value order, predictability and consistency.
Windows customers are not used to that. Windows Hello may be a good thing for them, but they don't expect the same degree of consistency, if your windows Application doesn't use it, they don't complain, this is life.
But apple customers, like you it or not, expect IOS features to be widely available on IOS applications. We literally pay for that, and as there are vastly more consumers like me, than developers like, it doesn't matter if we bought half the hardware you buy, because as a customer class, end users absolutely dwarf developers.
I completely understand your personal frustration. But this is on you, your choices of providing your work for free deliberately.
Most customers don't want to be back on the situation where you either choose between facebook login or tedious manual account creation, just because it will inconvenience some developers. The whole, raw point is exactly that. It may sound cruel, but we WANT you to be forced to implement stuff that is consistent with IOS guidelines, best practices or even features. Customers can be cruel like that.
I know it's frustrating for you, but this is the core of why Apple users stick to Apple. They decided to trust and share their data with one single company (Apple) instead of an overwhelming amount of small companies.
And it's not just about data; Apple users trust Apple to design a competiting device and a refined user experience and they don't have to do the work for themselves. They just buy the next Apple device and they trust Apple to do the work for them.
I know it's not for everyone, but if a subset of people like it and they decide to buy into it.... why are people getting mad? Apple is the result of what Apple users want. If you don't like them you can develop your app for Android users or whatever else you like.
As an Apple user I'm not happy they forced this. It's manipulative forcing even more platform lock-in for the average joe which empowers other anti-trust practices too.
You're argument that an Apple user is happy at the point of use doesn't justify anti-trust behaviour which is to the overall detriment of people.
Apple seem to get away with far too much just because they're 'Apple'.
Imagine the mess we would be in if every auth provider had the same policy.
But this is not something you can blame on Apple. You need to go to your politicians. You can't expect a company to self-regulate its dominance position.
In general I believe a much better way of dealing with this form of dominance is taxing the dominant companies agressively and use that money to fund open source competition.
X, Y, Z could be Apple, AppleID, and iPhone or Microsoft, Internet Explorer, and Windows.
Microsoft received a $611 fine in the EU for abusing it's Monopoly of control with Windows back in 2004 but it took many years to get there.
As an Apply user I'm quite happy that they keep devs on their toes. The industry as a whole went super user-hostile. Forced updates in Docker unless you pay, other apps doing bait-and-switch all the time.
Apply is like an island with cool shade from trees in the ocean filled with hungry sharks.
Are there any statistics on this? Apple never asked me if I wanted or liked the AppleID experience.
When AppleID came out, I thought it only worked on Apple devices so my use was limited to non-cross platform applications. With developers removing AppleID from Android applications, my initial misperception turned out to be justified.
I would still be happy they tried even if something like AppleID would turn out to be a bad idea, provided enough of these efforts turn into something valuable to me.
My understanding is that Apple only force you to include this if you provide other third-party login options.
This is a consumer-friendly feature that Apple is forcing you to implement so that your users on Apple platforms can choose to use your app's one-click third party login functionality whist still retaining control about what personal data they share with you.
Apple's platforms require a variety of consumer- and privacy-friendly features from developers who choose to release apps on them, and you could make your same argument against any of them (e.g. not tracking the user without their permission)
That Apple does this and holds third-party developers to standards for privacy and consumer-friendliness is why I (and many others) use their platforms.
The tone of your whole piece is sophomoric- you essentially suggest that all of Apple’s customers are uninformed and lacking agency (unlike you).
All of this because you could no longer automatically glom some people’s emails for whatever future use you dream up? I hope you realize how you’re coming off.
Frankly, I wouldn’t be keen on you having my email. You might accuse me of “sitting on my butt” or worse if you decide I’m not a good customer or whatever.
Please replace every mention of "Apple user" with "Apple". It really is the only wrong party here
Now you CAN choose to say, "I don't want those users", if they do not fit into your grand plan of things.
Apple does forward emails, so you can even contact those users for your password recovery use case you mentioned in other comments. I think your problem is not the fact that you do not have an email ID, your problem is, your users have the option of pulling the carpet from under you.
>To this date, I have sent 0 marketing emails trying to sell stuff. Heck, I don't even try to sell anything, I develop out of love and passion. The only reason email is needed is for password recovery
And your other reply in the thread:
>Frankly, I couldn't care less about whether you trust the app or not The fact is, I send 0 emails and privacy and security are top priorities. [...] TBH I am a bit tired of people trusting big tech so much.
Some constructive criticism about your replies... You come across as tone deaf.
Trust is not granted to you just because _you_ self-report that you're honest. Your comments will be perceived as another variation of, "Hey trust me, I'm an honest guy! Really!"
If you're tired of people "trusting big tech" so much, why would that have anything to do with you being "small tech" (e.g. Javier Antons's small company Collaborative Groups)?
The implicit cognitive consumer heuristic is not "He's a small unknown company -- therefore I trust him _more_ with my email address than a big company like Apple Inc."
You're focused more on your needs from a perspective of a developer instead of a perspective of an untrusting user.
That said, you definitely should remove Apple as an option if they make life as a developer not worth the time.
EDIT to add a link that may help your public relations strategy:
Fyi... your insistence on being perceived as trustworthy is a form of "countersignaling" and it makes people distrust your app. See https://en.wikipedia.org/wiki/Countersignaling
> Privacy means people know what they’re signing up for, in plain English, and repeatedly. That’s what it means. I’m an optimist, I believe people are smart. And some people want to share more data than other people do. Ask them. Ask them every time. Make them tell you to stop asking them if they get tired of your asking them. Let them know precisely what you’re going to do with their data. That’s what we think.
Some Apple users may not have cared as much about privacy until Cambridge Analytica and related issues, but it’s always been talked about at Apple.
I’d rather just trust one party, and have a single entity to complain to.
Where was that made clear? My best guess is when the author said:
> We are denied customer interaction, freedom to offer any non-Apple payment methods, etc. For example, I am absolutely sure that Groups would have had loads of more IAPs had I been allowed to offer Paypal on top of Apple Pay and what not.
Offering a non-Apple payment method is selling you stuff you don't want?
The post appears to be a thinly veiled attempt to cajole people into giving app developers access to their email inboxes as a general rule by throwing insults at Apple for daring to hide email addresses from app developers. Even if this person never tries to sell me things, that rule is clearly meant to enable other people to do so.
It frames "sending personalized emails" as though:
1) The only reason to send personalized emails is for "offering alternative payment methods".
2) Sending personalized emails is no big deal.
But both of those are wrong.
Now seriously, I have said time and time again that I have no issues with Apple ID. I have a problem with how Apple forced it on me. Not nice
Every single point you bring up is about you and not your users. All of your complaints in your post and in your comments in this thread ignore the fact that what Apple is doing is better for the humans on the other side from you.
And your stinger at the end?
> Apple users who logged into Groups via the app with Apple ID will need to create a second account. Am I hurting myself? Am I shooting myself in the foot? Probably. But this is war.
You're not hurting Apple. At best you're hurting your users, but you're so focused on your own petty brigade that you don't see it or care. The war that you've just started is not against Apple but against the human users using Apple devices. They're the ones who would suffer from your decisions.
Making the button uniform across domains so that it's instantly recognizeable is user-positive.
Offering Apple ID as a sign-up option instead of making me give you my email address is user-positive.
If you don't care about being user-positive, if you're going to vociferously argue against it, why should users trust you?
But it is the only way I can shed light on Apple's behavior. I promise to add a transition mechanism, happy? I will still make sure users get to read some "Apple bad" message to highlight the reason behind Apple ID not being straightforward on the web
It still sounds like Apple's behavior is 100% good for users and your behavior is not. You wanting to circumvent things that are positive for users makes you as a developer look extremely bad (user-hostile). I don't know what else I can say if you don't want to hear it.
I'm a user and I wouldn't touch "signin with Apple" with a 10 foot pole. That's waaaay too much lock-in.
For Apple device owners there's significant upside and little-to-no downside. You not wanting to use it doesn't mean that it isn't 100% good for Apple device users.
> That's waaaay too much lock-in.
If the app developer cared, they'd give you a way to migrate your credentials.
Anyway, you don't have to use it if you don't want to. Apple just makes it so that you have the _option_ to. But you should at least recognize that it's the only given option that allows people to use the service without giving away their email address to random app developers. That's a huge privacy win for users.
As a developer? Oh yes I do! That's exactly what we're talking about.
And it's not going to fly for very long because Apple has over half of the smart phone users in the United States. This is the reason we have anti-trust laws. They're going to be knocked down a few notches soon in my opinion.
That I can't build an app business in the United States without going through Apple is a problem.
They speculate about why Apple are so keen on people to adopt Apple ID - not say they actually want to do those things. I think they're probably correct about why Apple wants more control by sucking tech into it's ecosystem.
EDIT: Can someone explain how this is wrong?
And to be clear, Apple's policy does not require all apps to support Apple ID - only those which support another SSO solution like Google's or Facebook's. A malicious dev who wants to collect user data has no incentive to support SSOs in the first place. By not supporting SSOs, they can still collect user emails and abuse them however they'd like.
Apples solution of an anonymous email breaks this personalized tracking which is good for privacy concerned users but potentially “harmful” for app developers, particularly those that are ad supported.
There are many who wouldn’t see the value in adding Apple Auth and may actually see it as harmful to their businesses model and chose not to implement it which would deprive users of that choice.
This isn’t about a large section of app developers who just use social auth in a benign way, like the author, to ease app sign ups it’a about those that use social auth more insidiously to track users, frequently without their knowledge.
There’s not a feasible way for Apple to enforce this selectively so used a heavy hand. I feel for author with respect to the button guidelines but as a privacy minded user I’m glad he’s being forced to add the option.
However, Apple's policy gives malicious devs an obvious way out: just don't support any SSO solutions. So this policy doesn't really do anything to stop malicious devs at the end of the day. It stops them from taking advantage of alternative SSOs, but I wouldn't expect that to have much effect.
I guess maybe the policy is intended to mitigate the potential damage caused by negligent devs? As in devs who are not malicious, but risk allowing malicious actors to access user data through negligent design? That feels more like stretch to me, though.
The problem wasn't that the author couldn't access your precious email. The problem was that Apple used their power to force their auth solution onto the author, which means Apple has no incentive to make their solution good. It caused this developer enough grief that they intentionally removed support for Apple ID on other platforms as a small protest.
Please do not accuse people of malicious intent without evidence. You can discuss the merits of Apple ID without being a jerk.
No more giving Camera permission to an app just because it supports sharing photos, which you know you never want to do, or whatever.
(Yes, this was possible beforehand by manually refusing specific permissions after granting all, or vice versa. But it could be unpredictable and cause app crashes etc.)
I might want to use app Foo, I might even want to have an account on app Foo for syncing purposes, but that doesn't mean I want marketing emails, and spam, and all sorts of other crap from the makers of app Foo.
And, more importantly, all sorts of other crap from the companies that Foo decided to disclose your email to.
Or, just as often, anyone that has picked up my address from lists originally obtained via a hack of some sort because one of those entities has had lax security.
At the end of the day you've made your choice. You believe the reason Apple does this is to protect your privacy. You can't see that they want to close you in and make sure they are the only contact you ever have with anyone. This is to get your $. You're in fact paying a premium because they artificially inflate the price of every software you buy (think fees)
I don't "harvest" (fancy word) emails for anything other than basic password recovery, but just so you know, spam filters are pretty good these days
You don’t see that I want to only have to deal with one party. I don’t want 74637728 different logins if I can help it.
I want to not be forced by Apple to add things to my app. I want to add them willingly
You can keep trumpeting this, but as long as Sign in With Apple still works for password recovery (it does), then this is a straw man.
I don’t know you personally. Maybe you had a bad day, maybe you were still pissed about Google removing your app (wonder what that was about), maybe you just really love email addresses.
I don’t know why you did this, but your choice to punish apple users, to mislead them with that pop-up (it implies that it can’t be done, not that you chose not to implement 5 lines of code for personal reasons), and then chose to write a completely tone-deaf blog post about it, all tell me you are likely one of those devs I can’t trust. So I won’t.
I don’t care how upset you are with Fruit Co., you don’t take it out on Fruit Co.’s users. Who does one think one is, Epic?
Restricting Apple ID to the mobile app seems more than enough, the snarky popup goes too far. As a user, I don't care about your personal beef with Apple. Simply explaining that the button was added because of Apple's restrictions in the first place and that you never wished to support it in the first place should suffice.
I appreciate your willingness to lose customers to make a point against Apple. A little more... nuance would probably make it a lot easier to gather support from others.
I think he took his revenge from the wrong company...
But nevermind, it sounds more funny the way you put it
They belong in two successive paragraphs.
And the Google thing is a non-sequitur otherwise, given that most of the post he laments against Apple ID's requirements.
If you make me go through hoops or hamper my enjoyment/use of your app because I am an Apple user, I am going to stop using your app.
I'm not going to stop using an iPhone or the excellent "sign in with Apple" service just so I can run your app, I will find an alternative.
Is it really so inconceivable to some two-bit developer that I absolutely do trust Apple more than I trust them?
Hell, I trust Apple more than I trust Facebook and Google. Apple ID is my go to SSO these days. Is Apple perfect? No. But this is a game of lesser of evils.
You don't need to choose between Apple, FB, or Google. You can sign up with your email address, which means these companies get no analytics on your behavior
The reason "privacy" is in quotes is that some of us have started seeing through what Apple really means every time they use the word. As the EU's Executive Vice-President Margrethe Vestager has recently said regarding their Apple probe, privacy can't be an excuse to stifle competition.
https://appleinsider.com/articles/21/07/02/eu-antitrust-head...
You’re still missing it - we don’t trust YOU with our email address.
Before today we didn’t know who you are or what you stand for, and we didn’t trust you with our email address. After today, I’m sure I wouldn’t trust you with my private relay address, as you clearly care very little about your users.
I get it, you trust Apple. But are you Apple? If not, then why do you defend what is clearly very unreasonable and anti-competitive behavior?
I’m not you either, yet you ask me to trust you.
Please, just listen, because you’re clearly not getting it. Nobody knows you or trusts you. Many people, including myself, trust Apple far more than we trust you. This is because Apple has tens of billions of dollars in revenue from hardware sales. Selling some email addresses is going to bring a relatively paltry amount. I can’t say for certain they wouldn’t do it, but it would be really dumb. You on the other hand are much more likely to violate your users privacy because you don’t have another revenue stream at risk.
Sorry to burst your bubble but you can read all about how hypocritical Apple is about your privacy right here on HN - https://news.ycombinator.com/item?id=24109695
As I said: lesser of evils. I don’t care if Apple truly cares about privacy. I just care whether they will trample on it less than the others will, which I do believe, not because they care but because it might be profitable for them.
But good attempt, kiddo. You’ll get em next time.
We get it. Love Apple, trust Apple! There's not much else there.
Clearly the greater evil though is to enshrine one corporation to rule them all in the digital landscape. If we don't know that, then we haven't thought about the problem at all because we're trading short term security for long term insecurity. Read some Orwell or Huxley. Or just look at human history and how this plays out... what do we know about that? Anything?
Enjoy that! (Got 'em!)
Oh but we can go to Android! Gee, but we're talking about developers… You don't build a successful app business in the United States without going through Apple because they have over half the customers here.
To be clear: I'm fine with Apple signin existing. I am not fine with Apple being able to force every developer to dance to their tune just to be able to get at over half the smart phone users. There's a reason we have antitrust laws for this and not laws against two bit developers gaining your email and that's because one of them is the greater evil, but it's not the one you think it is...
For those who don’t know, SIWA is fully supported for web logins, and it’s implementation is pretty easy.
As the author seems to be active here, let me add my voice to those who are saying I will never choose to use an app written by someone with this level of disdain for me.
I liked the part where the author says Google and Facebook are good, but Apple is bad, and then two paragraphs later says Google betrayed him, but still prefers to make war on Apple.
I don't think Apple will notice or care. No one is going to drop their iPhone for "Groups".
Although I never said I liked Google, just that "all was well" with having 2 social logins. It sounds more funny the way you describe it though
If he actually wants to help users, he can let users click through via Apple login on his site, then ask those users to also authenticate via one of the other methods (e-mail, Google or Facebook) and link the two. That way, he would be able to let his users still log in to their accounts via e-mail if Apple tries to shut him down (like Google did temporarily).
I think his focus should be on limiting potential damage to his users, not exacting revenge against large companies.
They showed a screengrab of their app, and they had altered the design of the button, by filling it with gray (I agree that Apple’s choices are fugly). The writer couldn’t understand why Apple kept rejecting their app, and Apple’s rejection reason was not helpful at all (we often need to read tea leaves to figure out why our apps were rejected. It’s because they have a limited selection of canned responses).
Recoloring a branding element will definitely trigger a rejection. The Apple Brand is the most valuable brand in the world, and they won’t brook having it reinterpreted. No corporation would allow this, if they had a choice.
I'm not smug. I'm battle-scarred. I'll lay odds that I've had a lot more rejections than you have, and probably gotten a lot more pissed off at Apple.
Being an experienced Apple developer (since 1986), means that I have been incandescent with rage at Apple -many times. All of us have. Apple can be a real pain to work with.
I still develop for Apple, but I am not a "fanboi."
BTW: The rejection reason says that, because it's canned. It covers a lot of areas. I have received many such vaguely-worded rejections, and had to figure out why they bounced the app. In a couple of cases, I have been able to get people on the horn (PROTIP: Don't be calling them "smug," and be polite, even though you want to throttle them), where they have explained the issue.
[EDIT]: Also, branding is something that a lot of geeks don't understand, but it is very important (and valuable). Many of the seemingly insane moves by Apple are because they are building and/or protecting their brand. That "smugness" is actually a deliberate part of their brand. I don't think that it's a good idea for their fans to reflect it.
In terms of branding, a corrupted branding element is exactly the same as no branding element (except it's legally actionable).
Speaking of which, did anyone see this week's John Oliver show? I get the feeling that HBO is a bit peeved with Disney.
> That "smugness" is actually a deliberate part of their brand.
I wasn't calling Apple smug, though?
I was calling your comment smug, because of 1. implying it's unreasonable to say "kafkaesque" despite Apple setting up a system where you need to "read tea leaves" instead of believing what they tell you, and 2. phrasing it as that they "couldn't understand" the problem.
Your advice, as far as saying they use canned messages that merely resemble the actual problem, is very useful. But don't be mean to someone that doesn't know that. It's a major failing on Apple's part.
I wasn't being mean, and I apologize for a poor choice of words.
I love developing Apple software, and heartily support you in your endeavors. Please consider me an ally.
I sincerely wish you luck, but Apple can definitely be ... interesting to work with.
I understand that you are one of the most senior members of this community, and I certainly appreciate the work that y'all have done, trying to keep this from turning into an ugly community.
I really (truly) appreciate the decorum here, and sincerely do my best to respect that. It is my goal to be a positive, contributing member here. I may be mistaken, but I do believe that I have some contributions to make, here.
I may come across as a stuffy old fart, but that is a deliberate departure from my earlier days, when I was ... not that way.
If you force me to use email login, I’m going to feed you a burner email (thank you fastmail!) and call it a day.
The difference with AppleID is that I get a much better experience, my device automatically does what I would do anyway.
You don’t want to support a feature? It’s you app, do what you want. But the post reads like some lame justification (and a petty one at that).
Working in academia where OAuth2 is now (finally) being pushed heavily by certain converts who look upto "big tech" as having all the answers. It's annoying obvious to the people having to work this however that big-tech in this case is way behind where they could be in this regard.
It's not "simple" there's always money and power which the article alludes to, but as a user, I just want my account of "me" where I can use secure tokens issued from each authority once they've accepted that I'm probably me.
Until this is all resolved and unified a lot of this song and dance just reminds me I'm more and more the paying product for most systems.
Edit: It seems that 2 weeks ago you had a beef with Google as well. Maybe this blog is your way of venting the sorts of frustrations that come with developing your app. To offer some unsolicited advice. Take the time to learn and fully understand how the social logins work, and focus on providing the best experience possible. Badmouthing Google and Apple(and is Facebook next?) is not the way to get traction.
I don’t understand the end game here. Users are annoyed about lack of Apple ID sign-in on the web and so stop buying Apple products as a result?
Maybe make your app a Progressive Web App, make it with Flutter and available everywhere besides iOS, stop (or don't if you haven't yet) buying any Apple devices, sell the ones you can't root and put Linux on the ones where it's possible, start or join an anti-Apple group that pushes against it spreading, etc. Maybe that'll be more effective.
The effort is appreciated though.
Apple mandates changes all the time, and mandating Apple ID if you already use 3rd party logins is about the least controversial thing I can think of, and the most uncontroversially pro-privacy, pro-user, with incredibly small drawbacks and requirements feature I can think of. iCloud Private relay comes a close second on real user benefits (there are certainly way more drawbacks for the web at large).
At least it's decently documented (try Homekit documentation for a counter point), it's really not a huge job to implement, and there's a clearly stated purpose, force developers to give a "social" sign up that won't harvest their data.
That's exactly the kind of leaning on devs that's a 100% win for end users and that I, as a user and dev expects and wants to see from them. Less unannounced/undocumented screen saver api changes please, though, but I wouldn't cry a tear either on a ban on 3rd party "SDKs" that harvest any data.
Personally, I think adding a Facebook login to an app is a terrible thing to do, and the excuses of "just because it's convenient for users/will increase my signups" just don't fly with me, but that's just my strongly biased opinion.
Ranting (so inaccurately) to your users like that though? I think we can come to a broad consensus that it won't achieve a thing and doesn't exactly will fill your users with confidence about what you do with their data?
Privacy is a nice plus but for me, the best part is precisely what is pissing this guy off.
Also your revenge is not on Apple. They’re a behemoth and won’t notice. You pointed this out in your post so you are obviously aware of it but the only people you are hurting are yourself and your users. If you know this and willingly charge along, all I can say is that says a lot more about you than it does about Apple. Good luck.
hm. I can't see it as a bad thing that there weren't a ton of additional IAP micropayments in an app.
When does it stop then? If Spotify releases their app to the store, do they have to include Apple music functionality in their app? If I have an app with a "listen to this on spotify" button, do I also have to have a "listen to this on Apple music" button?
See no evil, I guess.
Instead of yelling angrily at the clouds, maybe focus on copy writing and graphical layout, if you want your product to go further.
I don't think shooting yourself in the foot is necessarily a strong tactic in war.
The post comes across as angry and immature.
I you use Apple ID, Apple gets the info which services you are using. The service might request additional infos about your person. Most people will always confirm that in reality. This way many services will end up with more user information. Many people will just share everything but might think about it if they needed to provide this info manually.
It is maybe a privacy feature because Apple might be better than Google or Facebook. Well...
My mail provider would need to parse my mails to get info about what services I use. Identity providers have those apps registered and grand token for specific services. They know exactly when a user is logging to specific services. This data doesn't even need to be evaluated further, Apple would have a neat list about the services you use.
Still, the usual mail registration offers more flexibility and gives the user more control. So, email registration is a privacy feature if you argue like this.
Security wise it is a decent solution, but also a single point of failure. It is hard to argue this to be a privacy feature. It is only one if you trust Apple more than the other services and different forms of auth isn't possible.
And that is why I am still an Apple customer. Or, 'prisoner', by author's words.
I haven't used any JS framework other than what's absolutely necessary for running the few WASM components
It’s not Apple he’s hurting.
“Since we were coerced into supporting Apple’s sign on with our iOS app, we’re sandbagging them in return by not supporting their sign-on here.”
If Apple ran off a cliff, would you?
I don’t care about your app and I don’t care about maintaining yet another stupid account. And I don’t want your emails. Sorry.
Where as the advert for an apple keyboard gets voted right to the top
I would be most happy if Apple was the only one out of Big Tech to get regulated. Let them have their Microsoft moment, and for the wolf to lose it's fangs.