Apparently It's OK For iOS Apps To Ask For Your Apple ID And Password
Apple's currently featuring the Sunrise app in the App Store. — Upon first launch, Sunrise invites you to create an account, then asks you to add a calendar. The first option, “iCloud Calendar” …
Context & Ripple Effects
Sunrise has been on a rollout: the social calendar app reached the iPad earlier this month (its January 9 iPad launch), and Apple is now featuring it in the App Store. But the featured onboarding flow asks users to type their Apple ID and password straight into the app to connect an iCloud Calendar — and, as Marco Arment's post and Sunrise's own response make clear, nothing in Apple's rules stops it.
The friction sits inside a longer argument about who owns identity on mobile: back in 2011, Dave Winer argued the future of identity belongs to Apple and Google, and this episode shows the downside of that concentration — when one company holds the keys, third-party apps that need its data have no sanctioned way to get it except by asking users for the master credential.
First-order effects
- Users setting up Sunrise's iCloud Calendar option hand their full Apple ID credentials to a third-party app, giving it everything needed to read mail, contacts, and purchases — not just calendars.
- Apple's editorial feature of Sunrise functions as an implicit endorsement of a flow that bypasses the platform's own sign-in UI, putting the App Store curation team at odds with the security posture iOS otherwise projects.
Second-order effects
- If a featured, well-regarded app normalizes typing Apple ID passwords into third-party apps, other calendar, mail, and contacts developers face pressure to follow the same shortcut rather than build around Apple's APIs.
- Sunrise gets a burst of attention from the exchange — a prominent critique answered by a same-day public explanation — which in an attention economy can outweigh the security black eye.
Third-order effects
- So long as Apple offers no first-party, scoped-authentication path for apps needing iCloud data, credential prompts will keep migrating into look-alike in-app screens, blurring the line between legitimate requests and phishing interfaces — a structural gap only Apple can close.
- The episode previews an industry fork: platforms either absorb identity themselves with delegated, revocable permissions, or every app-to-cloud integration becomes a trust decision made by the user at a text field.
The trend: As Apple consolidates its role as the identity layer for iOS, the lack of a sanctioned delegated-auth mechanism pushes third-party apps toward harvesting master passwords — making platform-owned authentication an inevitability rather than a design choice.