By John Gruber
WorkOS Radar:
Protect your app against AI bots, free-tier abuse, and brute-force attacks.
Remember the kerfuffle last week about iOS calendar app Sunrise asking users for their iCloud user name and password? Scary news travels faster than good, so I thought it worth pointing out that they’ve implemented a nice improvement:
Update: since our 2.11 version, we are not sending iCloud credentials to our servers, the app generates the secure token client-side. We use them to generate a secure token from Apple. This secure token is the only thing we store on our servers, we never store your actual iCloud credentials.
★ Friday, 31 January 2014