Apple debuts Sign In with Apple service, which masks info like email addresses, for iOS and non-iOS apps and web; mandatory for iOS apps using 3rd-party logins
Apple's new third-party login system will focus on user privacy, preventing user tracking. Tim Cook tells CBS News the move …
Context & Ripple Effects
Announced at WWDC and framed by Tim Cook to CBS News as a privacy play, Sign In with Apple lets users log into apps with a masked email address routed through Apple's relay, so developers never see the real address. A follow-up WWDC FAQ filled in the mechanics: two-factor authentication support and the private email relay service that does the masking.
The rollout was deliberately small — by September's iOS 13 launch only a handful of apps like Nike, Instacart, Bird, and Kayak offered it (WSJ's launch review) — but the mandate attached to it was broad: any iOS app offering third-party logins had to offer Apple's too. That coercion is exactly what Apple later walked back, replacing the hard requirement with a softer rule demanding some equivalent privacy-protecting option (the 2024 policy change).
First-order effects
- Developers shipping iOS apps with Google, Facebook, or other third-party logins must now integrate Sign In with Apple alongside them or face App Store rejection, adding work ahead of iOS 13's fall release.
- Users who choose Apple's button hand apps a relay address instead of their real email, cutting off the email-based tracking and marketing lists that login providers and app publishers previously captured.
Second-order effects
- Google, Facebook, and Twitter — whose login buttons sit next to Apple's wherever the mandate applies — are pushed to defend their own privacy credentials or cede the privacy-positioning high ground to Apple.
- Email marketers and analytics vendors lose a slice of addressable identities as relay addresses proliferate, shifting value toward whoever controls the identity layer rather than whoever collects the addresses.
Third-order effects
- If the pattern holds, platform owners use app-store rules to extend their identity systems beyond their own platforms — Apple explicitly targets non-iOS apps and the web here — making login a distribution and trust lever, not just a convenience feature.
- Mandates this blunt invite pushback: Apple's own 2024 softening of the requirement shows forced bundling tends to get renegotiated under developer and regulatory pressure, leaving 'equivalent privacy option' rules as the likelier long-term settlement.
The trend: Consumer login is consolidating into a platform-controlled identity layer where privacy masking is both the product and the enforcement mechanism.