Sign In With Apple Exposes Users to Security Risks, OpenID Foundation Claims

The foundation is asking Apple to make Sign In with Apple compatible and interoperable with OpenID Connect.

Advertisement
By Gadgets 360 Staff | Updated: 2 July 2019 14:07 IST
Highlights
  • Sign In with Apple will work on apps and websites
  • It is natively supported on all Apple platforms
  • Sign In with Apple can also work in Web browsers

Sign In with Apple was unveiled alongside iOS 13 at WWDC 2019

Apple announced its “Sign In with Apple” feature with much fanfare at WWDC last month. Meant to be a brand-new way for the Apple users to log into apps and websites without losing their privacy, the feature has now been called out by OpenID Foundation. The foundation says that although Apple has used significant parts of OpenID Connect for Sign In with Apple implementation, its code is not completely aligned with OpenID, leaving the users vulnerable to security and privacy risks.

In an open letter to Apple's Senior Vice President of Software Engineering Craig Federighi, OpenID Foundation wrote, “the current set of differences between OpenID Connect and Sign In with Apple reduces the places where users can use Sign In with Apple and exposes them to greater security and privacy risks.”

The foundation has also detailed the spec violations as well as peculiarities in Sign In with Apple implementation, at least one of which is known to enable attacks. Other violations and peculiarities mostly seem to hamper the interoperability of Apple's solution with OpenID Connect partners. It is unclear if any of them pose any security or privacy risks to Apple consumers.

Advertisement

The OpenID Foundation is asking Apple to address the gaps between Sign In with Apple and OpenID Connect and make it compatible and interoperable. The foundation is also asking Apple to join it.

Advertisement

Apple has said to have fixed one of issues pointed out by the foundation. So, the company is clearly paying attention to what OpenID Foundation is saying, but it remains to be seen whether the iPhone maker will do everything that the foundation is asking or just fix the security issues and keep its implementation independent.

To recall, with Apple ID authentication, Apple will just provide the app developers or website publishers with a random ID and keep all of users' data safe with itself. The company also said that it won't use the Apple ID authentication data to profile users or their activity.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. Motorola Edge 70 With 5.99mm Slim Profile Will Launch in India on This Date
  3. Be Dune Teen OTT Release: When, Where to Watch the Marathi Comedy Drama
  4. Vivo S50, Vivo S50 Pro Mini Set to Launch on This Date
  5. Gemini 3 Deep Think Model Is Now Available to These Users
  6. Google Could Soon Release Nano Banana 2 Flash AI Model: Report
  7. Nothing Halts Android 16 Rollout to Implement 'Urgent' Fix
  8. OpenAI's Code Red: 5 Things to Know About the AI Giant's ChatGPT Strategy
  9. OpenAI Says ChatGPT Isn't Showing Ads to Paid Users
  10. Realme Narzo 90 Series 5G India Launch Announced
  1. Google Could Soon Release Nano Banana 2 Flash AI Model: Report
  2. Oppo Find X9 Velvet Red Colourway Goes on Sale in India: Price, Offers, Features
  3. Nothing OS 4.0 Update Rollout Reportedly Paused to Implement ‘Urgent’ Fix
  4. Infinix Note 60, Note 60 Edge, Note 60 Pro Reportedly Spotted on SDPPI Certification Site; Specifications Revealed on Geekbench
  5. Bitcoin Steadies Around $91,300 as Crypto Market Sentiment Remains Cautious
  6. Motorola Edge 70 India Launch Date Announced; Confirmed to Feature Triple 50-Megapixel Camera Setup
  7. Battlefield 6's 'Winter Offensive' Update Launches This Week With New Content, Audio Improvements and More
  8. Chinese Brands Aiming to Win Users with AI Features That Apple Lacks: Report
  9. Samsung Ballie Robot Reportedly Delayed Again, Won't Launch This Year
  10. Vivo S50, Vivo S50 Pro Mini Launch Date Announced; Colour Options Revealed
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.