Being this angry at having to give users the option of better privacy really isn't a great look.
Which used to offer both social sign-up (FB and Google) and a traditional email sign-up option
You probably don't know that in this case, Groups was also forced to include AppleID or risk being removed from the App Store
Removing all social logins from this point to ensure compliance would have definitely affected all users who had originally signed in with FB/Google, way before AppleID ever existed
Yet it would have been more consistent! What is the point of going to war against Apple while embracing the private-data-broker model at the same time?
Just send a warning e-mail requiring password change because you decided to remove all social login as a protest.
And provide a password reset mechanism for formerly social-login users that haven't defined a password in time.
That would have been a true act of resistance.
Apple decided to prioritise users over developers here.
As a user, I am very satisfied that Apple made this a requirement.
As a developer, I just implemented it without throwing a tantrum.
1 - Activation email with activation code to ensure the person actually owns the email address (non-OAUTH sign-up)
2 - Password recovery for when they have forgotten their password. Yes, a user doesn't need this with OAUTH but sometimes they will have forgotten that they used OAUTH to start with and need to sign in with email & pss
3 - When push is turned off and someone has messaged you
I don't think this is beyond reasonable but I'm willing to take criticism
And I think Apple's behavior should change so I am making this public
Because this response tells me you’re willing to compromise your user’s experience because of your personal issues with Apple.
As a user, this does not give me confidence in your decision making.
It’s somewhat understandable to be annoyed, even angry at Apple. But the moment you decide to pass that on to your users is the moment you’ve forgotten the most important humans in this story.
Of course, it’s your right to do what you want, and if that means taking a stance against Apple ranks higher than your user base, I suppose that’s your prerogative.
But that definitely would make me hesitate to use the app.
I don't even hold a grudge against Apple. This is just me trying to make the world a better place. It's in everyone's interest that Apple doesn't gain authority to force us to do things (don't forget, devs also are Apple customers)
On the other hand, I absolutely trust Apple - my relationship with them spans over a decade and countless products/experiences.
I’m happy that they’re forcing devs to offer Apple Sign On as an option when other social logins are also offered. As a user, I trust Apple far more than any 3rd party dev.
I pay a premium to Apple because of their platform and the types of things they enforce.
I want you to understand that as a user, this is exactly what I want Apple to do and I pay extra for it.
This reads like "I know what's best, despite what Apple users say they want, and I'm going to make the world a better place by ignoring my users and telling them what they want is actually bad for them", despite the fact that this is actually a beneficial feature to users, even if it could be construed as a benefit to Apple as well (arguments can certainly be made).
> It's in everyone's interest that Apple doesn't gain authority to force us to do things
The rulebook to participate in this ecosystem is a mile thick. Why is this the issue that you choose to make a fuss over? There are a a myriad of other rules that are even more heavy handed, that actually are to the detriment of end users to protect Apple's walled-garden.
Picking a feature that arguably makes user's lives better seems tone deaf at best, and actively harmful to a broader message about openness at worst.
Petulance does not become a developer. The last time I saw a tantrum thrown this much was when my kid was 5 and had a major meltdown over a lack of chocolate ice-cream.
He didn't get any ice-cream for a week, a response that taught him meltdowns don't work.
Now I ask you this: how far are you willing to go to further a good cause? Watching from the sides feels more comfortable, but we are being decimated and doing nothing won't change a thing. We need to act now, or watch our profession/hobby/passion be used to fatten the already morbidly overweight big tech companies
But what, exactly is the "good cause" here? Is the good cause to force Apple to stop delivering an experience that we've already established throughout this thread is an experience Apple users want?
There are so many problems and battles to be fought in tech, so much abusive behavior, so many dark patterns. This is not that. If this is the cause you're fighting, I fear you've missed the forest through the trees.
Unless you had something else in mind, in which case I'm genuinely curious.
Enslaving the entire Uber driver or deliveroo poor sod population is arguably beneficial for users. But, is it right? Plenty of jurisdictions have already spoken that these workers have rights. Nobody has made a ruling regarding developers yet
The "iMentality" can't possibly extend to wishing that Apple treats other human beings like **. Can it? If so, we may have gone back in time to even before the 1860s
hobgoblin33@ussr.ru doesn't carry much info.
Just googling someone's email is a start. But worse actors can find your email on a combolist or figure out what other services you use. Just knowing someone's email is the first step to social engineering a customer service backdoor, for example.
AppleID specifically helps users avoid all this with trivial per-app email address generation, and that's something our tools should have given us a decade ago.
I don't care. I don't trust you. I don't trust any of modern devs, I see every other new shiny crap on the internet only as an attempt to extort me of data and/or money (subscription) now. Before Apple introduced that feature I was using email aliases in my Fastmail. Need to register in new service - go to Fastmail, generate an alias for some weird domain they've got, setup filter for it to go to "dodgy" folder and then register.
Now I don't need to do that anymore, Apple automated that for me.
And thank's Apple it also forced guys like you to allow me to use that automation. At least on their platform.
For same reason the only way I buy a subscription is through an in-app-purchase - because I can just to go App Store and cancel it and don't need to deal with people like you. I remember like an year ago I was waiting for a refund for a cancelled subscription and my emails were ignored and the only way to get the attention was to open a dispute in PayPal. Yet another supplier-hostile but consumer-friendly company. Thanks god they exist.
Apple could be considered a genuine neutral arbitrator if it didn't take money from both the developers and its users. What it has done instead is to force itself between the user and the developer, and exploiting both in the name of the users (developers lose money to Apple's extortion, and the money it extorts from the developers is ultimately passed to the user, and thus they end up exploited too).
And even if they do, too many developers couldn't give two shits. Great example is how users overwhelmingly opt-out of tracking when the OS warns them about it (because "developers thinking about users" never even considered not tracking)
Like minded developers are not just fighting Apple, but the whole attempt by "big tech" to move to the business model of exploiting developers by controlling distribution of softwares, and dictating terms that favour them. This ends up harming both developers, as they earn less, and users, as ultimately it the user who ends up paying the share of profits that Apple (and others) extort from the developers.
I wonder what it would take to "force" me into doing a social login? It would have to be something drastic, like a website that provides me with needed oxygen.
To get on my hobbyhorse some: what about a platform that your employer uses to distribute relevant documents and updates which you need for your job, which has become sufficiently well-known and implicitly available that hesitating about the dependency is perceived as bizarre?
Note that the response of “don't deal with them then” runs into market information and churn amplification¹ issues when it is a social assumption that picking up a ‘tool’ (which is actually a relationship with a third party, but where this is close to invisible in the steady state) is essentially a free action which requires no consideration, because the information about “does this employer require me to use this tool” neither propagates efficiently nor stays stable.
Past source: wound up changing the email address on one of my Google accounts recently for exactly that reason. They actually asked me up-front whether I had a GMail account they could use instead, which turned out to be because they use restricted Google Docs for critical material. Not naming them, but in a broad sense, this is one of the more ethical companies I've ever dealt with, by the way.
Future source: I should probably be considering digging into LinkedIn soon despite their past abusive behaviors, because as it turns out, if I want to dig myself out of this hole…
¹ I assume there's a ‘real’ term for what I'm thinking of, but I don't know what it is, so I cobbled that one together out of the most relevant-seeming bits.
Apple has never shown me hostility. On the contrary, I found Apple to offer reasons why they do things and how to work around them. Have they sometimes forced me to do things I don't want (and felt were worse)? Yes. But it was obvious what I needed to do to comply.
Restrictive is not the appropriate word.
For example, this whole forcing devs to use "sign in with Apple" is not about imposing restrictions as you can decide to not use a third party sign in (on a new app).
Apple is saying "hey if your users can sign in with Facebook they should be able to sign in with Apple, we want a piece of the pie". Some iOS users are happy about the privacy aspect of this but fundamentally (IMO) this is not about privacy or restrictions, it's about making users and devs more dependent on the Apple ecosystem.
If they made it optional, a large percentage of apps would force you to use Google/FB to login. That's not acceptable to me.
One of the major reasons I give Apple money is to because they can stand up against the privacy invading FB/Google and I, as an individual, cannot. So they are very much doing what I want in this instance.
It's explained in my previous comment.
Not well enough for me to understand, because I asked what you meant.
Apple does the same thing. As a dev once you open the door to using Apple you're forever stuck with that. As a user, it entrenches you further into the Apple ecosystem which is ultimately the whole Apple product strategy.
I like this result as a user.
I have to be honest here and say that I amazed, but sadly not surprised by the level of entitlement on display from a very small but extremely vocal set of developers.
My behavior? You have no idea what I do. I don't even develop for Apple platforms.
> Why should your user have to use an anti-privacy 3rd party like Facebook to use your app or service?
I would never use anything by Facebook. Not sure where you got that from.
> Where is the users choice other than to not use your product?
That is choice.
> I amazed, but sadly not surprised by the level of entitlement on display from a very small but extremely vocal set of developers
As a dev shouldn't I be able to have control over my application?
But I wouldn't want any of those companies know which services I use. I am fine with using Auth0 or other third party providers, but only if I have to.
You don't even need to verify the mail in my cases, you could even use a completely fictious one. Clean, easy, anonymous.
Not really sure about smartphone hell, but most identity providers offer up the mail of the user anyway. Maybe that is different in phoneland though.
I used to prioritize the domain's own login, but now I'm starting to mix in some logins with Apple... I just prefer to have _less_ people have my personally identifiable information.
I run my own mail server so it's easy for me to implement vendor-specific email addresses that cannot be correlated with other vendors', but more and more companies are offering that as a service nowadays, DuckDuckGo most recently:
https://www.spreadprivacy.com/introducing-email-protection-b...
I do use GitHub federated login, but only for apps like vulnerability scanners that do need OAuth access to my repos.
Neither is a good thing
If I were to write an iOS app, I likely wouldn’t. I don’t trust myself handling that kind of thing securely.
You don't get anything beyond what you ask for AND are granted access to by the user.
FB login gives email and name AFAIK, but you can ask for lots of other stuff and be denied. Google defaults to email, not sure about name, and has separate requests and grants for any additional information. They don't have nearly as much of a profile as FB does, but can give address and some other details. Apparently Apple doesn't even provide a real email, so that seems even better for "collecting [your] personal information" than using... your personal email address!
Social login is much better than storing passwords in any form (plaintext, encrypted, hashed), and gives both the user and site owner the benefit of FAANG security.
Users want
- Easy access
- A familiar experience
- A consistent experience
- To avoid more passwords
They generally are not aware of the privacy tradeoffs they're making by using social login.
I'd argue that if the developer truly wants to fight the good fight, they should remove social login altogether.
I find it odd that the options they support willingly are the options that are most user-hostile from a privacy perspective while the option they begrudgingly support (while making a big fuss about it) is the one option that actually tries to protect the user.
I'm really annoyed Vercel stopped offering email signups.
The part where the developer puts the word 'privacy' in scare quotes is a bit of a red flag for me. Suggesting that "accept[ing] two "social logins": Google and Facebook. All was well." does not fill me with confidence that the developer respects privacy concerns.
iMessage backed up on iCloud where Apple has key to decrypt.
>“We specifically don’t collect data, even from point A to point B,” notes Cue. “We collect data — when we do it — in an anonymous fashion, in subsections of the whole, so we couldn’t even say that there is a person that went from point A to point B. We’re collecting the segments of it.
The segments that he is referring to are sliced out of any given person’s navigation session. Neither the beginning or the end of any trip is ever transmitted to Apple. Rotating identifiers, not personal information, are assigned to any data or requests sent to Apple and it augments the “ground truth” data provided by its own mapping vehicles with this “probe data” sent back from iPhones.
https://techcrunch.com/2018/06/29/apple-is-rebuilding-maps-f...
Google Maps:
>Google Maps won't let you save home address without allowing all Google tracking
https://news.ycombinator.com/item?id=18070183
and
>An Associated Press investigation found that many Google services on Android devices and iPhones store your location data even if you’ve used a privacy setting that says it will prevent Google from doing so.
https://apnews.com/article/north-america-science-technology-...
2011: iPhone's Location-Data Collection Can't Be Turned Off - https://www.wired.com/2011/04/iphone-location-opt-out/
"Your iPhone tracks your location for a variety of reasons. It tracks you to calibrate sensors and to improve services, but also to show you ads."
2019: How to stop your iPhone from tracking your location - https://www.cnbc.com/2019/12/19/your-apple-iphone-tracks-whe...
2019: It’s the middle of the night. Do you know who your iPhone is talking to? - https://www.washingtonpost.com/technology/2019/05/28/its-mid...
"The best way to keep something secret is not to capture and store it in the first place. And that’s the crux of the privacy versus convenience debate now redefining our applications and software-based services ... Yes, maybe what happens on an iPhone stays on an iPhone, but some data should not be captured in the first place. Nothing more so than the significant invasiveness of Apple’s significant locations concept—a perfect illustration of just because you can, doesn’t mean you should. This is a continually building data repository of the locations you visit, along with times and dates, detailed maps, even the mode of transport to get you there and how long it took."
2020: Why You Should Stop This ‘Hidden’ Location Tracking On Your iPhone - https://www.forbes.com/sites/zakdoffman/2020/10/04/apple-iph...
“Both iOS and Google Android transmit telemetry, despite the user explicitly opting out of this,” wrote researcher Douglas Leith from Trinity College in Ireland, in a recently published academic report ... “To date, Apple have responded only with silence (we sent three emails to Apple’s director of user privacy, who declined even to acknowledge receipt of an email,” Leith wrote. Since then, Apple has made public statements critical of Leith’s research and insisting privacy and opt-out measures do exist.
2021: Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out - https://threatpost.com/google-apple-track-mobile-opting-out/...
"And there’s also a more fundamental issue with this technology. Its euphemistic description as a “crowdsourced” way to recover lost items belies the reality of how these items are tracked. What you won’t find highlighted in the polished marketing statements is the fact that AirTags can only work by tapping into an Apple-operated surveillance network in which millions of us are unwitting participants."
2021: Remember, Apple AirTags and ‘Find My’ app only work because of a vast, largely covert tracking network - https://theconversation.com/remember-apple-airtags-and-find-...
------
As for "anonymising" user data, Apple has enough data points on its users from various services and sources it collects its user data from to make it meaningless.
There is a lot of profit in collecting and monetising user's data - Apple's shareholder will not allow them to leave it on the table. Apple knows that as it was part of the PRISM program and earned a lot of money by supplying the US government it's users data. (Apple also dropped plan for encrypting backups after FBI complained - https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... ). And on a different note, in the early years, Google too begin it's spying and data collection by convincing its users that it is a "decent" company.
https://appleinsider.com/articles/21/07/02/eu-antitrust-head...
All was well because nobody was forcing me (the developer) to include anything I didn't want. Users could still use traditional email signup. You are free to choose whom you trust. If your choice is Apple, well, that is your choice
In. A. Heartbeat.
You claim (elsewhere) that you only send responsible-sounding emails, but the level of invective in your screed leads me to disbelieve you. Personally, I think HME seems to have been created exactly to cope with people like you - and I’m failing to see this “hype” you talk about.
HME makes the value of an email address tend to zero, gives me the ability to cut you off without your agreement (and prevents you from selling my email on afterwards), and places all the control in my domain not yours. That’s simply the truth of the matter, and it’s not hype.
I don't challenge that Apple ID is a good thing. I protest Apple's method of implementation
I distrust anyone who tries to downplay privacy as important.
I distrust anyone who tries to brand a genuine privacy upgrade as "hype"
And, frankly, signing in (with AppleID or not) doesn't prove a thing one way or another. The OP could be simply harvesting email addresses and selling them off later[+]. (S)he could be upset that HME and SIWA are a threat to that business. Far-fetched ? Sure. More far-fetched than an adult throwing the tantrum on the website ? Not so sure...
Or another option along the same lines. Perhaps OP has another more-public site that (s)he doesn't want to take this stand on for PR reasons, so they're doing it here, and getting "awareness" out there by submitting to places like HN. In that case, sure, there'd be no email abuse on the <don't care about> site...
There's a few other options that are possible. None of these get around the basic premise that privacy on the net is important (at least to me, YMMV) and I don't trust those who decry it.
[+] Tesla does this, for example. All of a sudden, a couple of years after buying power walls, I'm getting emails to Tesla@<my-domain> and texts containing Tesla@<my-domain> to my phone number (which I usually obscure using google-voice) asking if they can give me mortgage offers (for example). Tesla sold my details when I stopped buying expensive stuff from them - this is why I set up a catch-all address, and used <company>@<my-domain> whenever I signed up for stuff. Now I use HME.
They don't seem to be able to grasp that maybe there are different viewpoints in this world. Maybe that's even a good thing, and perhaps denigrating entire swathes of people as "fanboiz" says more about the person doing it than about the people they're complaining about.
Just maybe.
You mean like you're doing?
Kettle, meet Pot.
I particularly like this Apple fanboi argument - that having a third party (Apple) needlessly involved is somehow more "private" than only just the 2 primary parties being involved.
>I'm a Brit
Well I guess that explains a lot then - you're probably one of those that also voted for brexit, but now completely denies it - right?
Maybe you're a good developer. And? How many sites on the internet do you think I'll have to trust before it backfires?
> I protest Apple's method of implementation
How else could it have been implemented that would have led to any reasonable adoption rate?
Offering Apple as a choice does not remove the customer's ability to use the two biggest names in surveillance capitalism as the "protector" of their privacy.
I agree. I only create accounts for things reluctantly. Because 1. Why do you want my email address, or DOB, or whatever else? I don't want your marketing, and 2. I can't be bothered, I downloaded your app because I have something I want to get done.
Because Apple's SSO will not be eternal and nobody wants to have a tier as a proxy on an important account credential.
Apple SSO is ok for throwaway account where your account has no "sentimental value" that you can't recreate easily. But the author of this post maintains a social network : nobody wants to be locked out a social network.
I have active accounts on websites that existed back when Apple was fighting not to die and I would have totally lost access to them if I had to sign-in to them through my Lycos account.
Don’t use apple SSO because apple might not exist one day?
You may as well argue not signup to anything using gmail because, heck, google might go out of business.
There is no benefit to users in giving your “real” details to service providers; the benefit is entirely on their side.
You can argue that Apple is harming the opportunities for 3rd party developers, sure, taking advantage of them? Sure.
…but let’s not try to frame this as somehow “pro consumer” to give your email away so people can spam you with notifications and offers to lift their engagement rates.
That is pure BS.
I assume OP point is that Apple or Google could still exists but your accounts might not exist, maybe you get banned or just decide you don't want to use Apple/Google/FB anymore.
I don't agree with GP's fear of Apple SSO vanishing without a transition period to something else, but the general premise that this form of login is not eternal but rather short lived in the grand scheme of things is reasonable and doesn't warrant your aggressiveness.
Also you might get locked out of your Apple account for a number of reasons and will then lose access to much more than just Apple services.
I fail to see any problem with this.
There might be a day when Apple is not _my_ cell phone platform. Even now I have an Android phone and iPad and I prefer to have access to same services from both.
I personally avoid to do it, but that's not the point.
Every other third party allows account recovery by mail : if you want to stop using FB or Google's SSO, you can ask the website to send you a mail to prove the account ownership.
If Apple's SSO stopped working (because Apple stopped it, banned you, because you dont have Apple devices anymore so you are locked out of their proprietary 2FA), none of those websites could send you a recovery email.
> That is pure BS.
I don't feel like I've been insulting, so please don't be either.
They have SMS as a fallback. I know it's insecure and I'd rather they support TOTP, but let's not pretend having an Apple device is the only way to receive 2FA codes for your Apple ID.
I pretend nothing, I just didn't knew it since I had an iPhone for years.
This line is unwarranted and in violation of HN rules. Be cool.
I learned something today. I didn’t know you could get SMS codes for Apple 2FA.
Yes. And more to the point, because that Apple service may not exist in the future. Or Apple may determine that a particular app or service can no longer use its service for whatever reason, and you as a user will not have any choice in that manner. It's all been done before.
Given an alternative storyline where Epic Games allowed users to create account with relayed apple mails, wouldn't all those accounts suddenly became unusable today ?
https://appleinsider.com/articles/21/04/20/man-sues-apple-fo...
So has Google, and presumably the other platforms as well.
For every service I’ve built allow the user to create an account with email, Google, Microsoft, Apple, Twitter, Facebook and to later untie their account and move to email. Also if they ever get locked out from their oauth account they can use the email to create a password and login via the normal way.
This is exactly my point ! You can't recover your account if you don't know the mail used for registration. Even if you remembered it, no check could be made if Apple stopped to proxy the mails for one or another reason.
With other providers, you could always recover an account because your email address would let you prove the ownership of the account.
This is the problem with one click account vs email entering. It is a risk users should be made aware of but it is still their choice. And for some critical services I'll use my email, for other like the app in question, or most apps on the App Store I'll use one-click install, also most of the time there is no need for me to have an account. Most data can be stored on device without the need for user authentication.
If they are locked out of the oauth account, presumably they can't check their inbox.
edit: Oh, do you mean you ask for an email address after they already flow through the oauth process - because that's the worst of all :)
I agree that in a perfect world you'd provide your real email address and solve this problem. But developers and companies have repeatedly proven themselves to not be trustworthy and the majority will misuse any contact details for spam which users do not want. In fact there wouldn't be a business case (nor appeal to end-users) for Sign in with Apple if this wasn't a real problem.
They may well offer notice and time when they cancel the service in some future.
They won't offer any of that if they happen to erase your account just because though, as has happened to many people.
https://appleinsider.com/articles/21/04/20/man-sues-apple-fo...
Actually, under that logic it's only that you shouldn't use the @gmail.com domain; it should be fine to use Gmail with your own domain, since that allows you to recover if your Google account is canceled (just change the MX to another email provider).
Another thing you can do is to never use your Google account for anything other than email; that should reduce the chances of the account being canceled for no obvious reason. For instance, it's been reported that, if you used your Google account for Youtube, and Google decided your real name was not your real name (which it wanted due to the Google Plus integration with Youtube), your whole Google account could be canceled; that risk could be avoided by just never logging into Youtube with your Google account.
Right, that's why. Don't ever use "sign in with XXX" for any value of XXX, whether apple or google. Any of them can erase you off their site on a whim and you've lost all unrelated accounts where you made the mistake to "sign in with XXX".
Create accounts with your own email, control your future destiny.
Any website offering SSO options would have a sunset period to move it over if a provider went under...and if they don't, they are likely defunct at that point anyways...