/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Apparently It's OK For iOS Apps To Ask For Your Apple ID And Password

Apple's currently featuring the Sunrise app in the App Store.  —  Upon first launch, Sunrise invites you to create an account, then asks you to add a calendar.  The first option, “iCloud Calendar” …

Marco.org Marco Arment

Context & Ripple Effects

Sunrise has been on a rollout: the social calendar app reached the iPad earlier this month (its January 9 iPad launch), and Apple is now featuring it in the App Store. But the featured onboarding flow asks users to type their Apple ID and password straight into the app to connect an iCloud Calendar — and, as Marco Arment's post and Sunrise's own response make clear, nothing in Apple's rules stops it.

The friction sits inside a longer argument about who owns identity on mobile: back in 2011, Dave Winer argued the future of identity belongs to Apple and Google, and this episode shows the downside of that concentration — when one company holds the keys, third-party apps that need its data have no sanctioned way to get it except by asking users for the master credential.

First-order effects

  • Users setting up Sunrise's iCloud Calendar option hand their full Apple ID credentials to a third-party app, giving it everything needed to read mail, contacts, and purchases — not just calendars.
  • Apple's editorial feature of Sunrise functions as an implicit endorsement of a flow that bypasses the platform's own sign-in UI, putting the App Store curation team at odds with the security posture iOS otherwise projects.

Second-order effects

  • If a featured, well-regarded app normalizes typing Apple ID passwords into third-party apps, other calendar, mail, and contacts developers face pressure to follow the same shortcut rather than build around Apple's APIs.
  • Sunrise gets a burst of attention from the exchange — a prominent critique answered by a same-day public explanation — which in an attention economy can outweigh the security black eye.

Third-order effects

  • So long as Apple offers no first-party, scoped-authentication path for apps needing iCloud data, credential prompts will keep migrating into look-alike in-app screens, blurring the line between legitimate requests and phishing interfaces — a structural gap only Apple can close.
  • The episode previews an industry fork: platforms either absorb identity themselves with delegated, revocable permissions, or every app-to-cloud integration becomes a trust decision made by the user at a text field.

The trend: As Apple consolidates its role as the identity layer for iOS, the lack of a sanctioned delegated-auth mechanism pushes third-party apps toward harvesting master passwords — making platform-owned authentication an inevitability rather than a design choice.