Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Apple Sign On Commentary
News & Analysis

Apple Sign On Commentary

ISB Editorial StaffBy ISB Editorial StaffJune 5, 20193 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Apple MacOS Devices Now Subject Of LockBit Ransomware
Apple MacOS Devices Now Subject Of LockBit Ransomware
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Apple let the public know that it has introduced a new way to stop third-party sites and services from getting your information when you sign up for an app. According to Apple software engineering chief, Crag Federighi, one-click sign on can be convenient for consumers but can come at the cost of users’ privacy. Personally identifiable information (PII) sometimes is shared behind the scenes and these logins can be used to track individuals.

To secure user data, Apple is introducing a feature to allow developers to add a “sign in with Apple” feature that will authenticate users’ identities without turning over any data to a third-party company.

Apple's single-sign-on feature isn't as sexy as a new phone or operating system, but it could have an massive impact on user security and privacy for years to come https://t.co/L3d6Nmq3nC

— WIRED (@WIRED) June 5, 2019

Expert Comments:

Ben Goodman, vice president of global strategy and innovation, ForgeRock:

“Yesterday’s news of “Sign in with Apple” forces the issue of organizations and providers to modernize their authentication methods, and places Apple at the forefront of this shift. This new capability moves securing identities beyond user names and passwords toward tokenized authentication. By tokenizing login Apple potentially eliminates passwords all together, which are the weak link in the security chain. This is different than typical single sign on (SSO) via Face/Touch ID, which still contains a username and password which can be hacked.

Consumers are becoming hypervigilant of being aware of how their data is used by organizations. And they gravitate towards companies and vendors that both show respect for their privacy and give them controls to manage it. Apple is betting big on this and has made end-user privacy a key pillar of their strategy. The new “Sign in with Apple” capabilities provide consumers the convenience of other SSO and rapid registration tools, but Apple’s business model prioritizes privacy over data collection.

As well, this new feature from Apple supports better identification of users from the start of managing an identity. We’re beginning to see these identity schemes from organizations that are seen as “anchors of trust,” such as banks, governments and telcos. And Apple is positioning itself as one of these “anchors of trust” by incorporating privacy and service from the outset and providing a better way to authenticate user identities, without trading seamless sign on capabilities and privacy for access to data.

However, implementing all of these different methods for SSO will be difficult for many businesses and application providers. In addition to the raw overhead of having to support multiple authentication and registration schemes in every app, there is the danger of overwhelming the users with too many authentication options, especially if an option doesn’t apply to them in their current context. This is why business and app owners need an identity platform that can support all of these different schemes and provide many options to integrate them into applications. As well, the identity platform needs to be intelligent enough to understand the end-user context and only present them the authentication options which are relevant to them.”

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}