Live data from Hacker News

Open Letter to Mozilla: Bring Back Persona

stavros.io

11–20 of 243 posts

Re: Open Letter to Mozilla: Bring Back Persona

#13
post #5

I hate that the best user experience for logins is "Login with facebook" or "Login with Google". I don't want to impose that privacy failure on my users, but I also don't want to impose the annoyance that is "Sign up with a username, email address, and password". Offering all of the options is also a compromise that complicates the user experience. Now, here's the sad thing, for me: I didn't even know Persona existed…

Side note: usernames should just be emails these days, they're unique and save all the effort of needing another made up name.

Theoretically yes, but it's not as simple as that. Every identity can have more than one email associated with it, and emails can change over time. So "username == email" is fine as long as the concept of a username mutating is fine.

Re: Open Letter to Mozilla: Bring Back Persona

#15
post #5

I hate that the best user experience for logins is "Login with facebook" or "Login with Google". I don't want to impose that privacy failure on my users, but I also don't want to impose the annoyance that is "Sign up with a username, email address, and password". Offering all of the options is also a compromise that complicates the user experience. Now, here's the sad thing, for me: I didn't even know Persona existed…

Side note: usernames should just be emails these days, they're unique and save all the effort of needing another made up name.

Services that don't require email for functionality shouldn't require email addresses at all. An excellent example of this is reddit.

Re: Open Letter to Mozilla: Bring Back Persona

#16
- Can Mozilla set up a kickstarter for this project?

- Is it technically possible to create a Bash/SSH integration? The Linux world pretty much has SSO now, it would be an awesome argument to have this and Persona extend each other.

Re: Open Letter to Mozilla: Bring Back Persona

#17
> Anyone with access to your email account can simply reset any password on any site. The right solution is to make your email account very, very secure.

No, the right solution is to stop using email as sole identification for password resets. Yes, there are other solutions you can implement right now without waiting for some big company to save you.

The most obvious one it to create a second factor of authentication just for account resets. It could be via an SMS OR simply by asking user to print out/write down a special randomly generated "reset" number.

"But SMS costs money!" No, for most providers you can send an email to a special address reserved for the phone number. It will get translated to SMS automatically.

"But users will forget/loose their reset number!" Maybe, maybe not. It's a cultural thing. You don't expect them to loose access to their email, but that happens all the time.

Re: Open Letter to Mozilla: Bring Back Persona

#18

>Tell the email provider you want to give a site permission to know your email address, without telling the provider which site it is. Then the site emails you anyway. (If you didn't want them to, you shouldn't have given them your email address).

The email could be used for authentication purposes and not for actual email.

Re: Open Letter to Mozilla: Bring Back Persona

#19

Earlier quoted context omitted.

Side note: usernames should just be emails these days, they're unique and save all the effort of needing another made up name.

Theoretically yes, but it's not as simple as that. Every identity can have more than one email associated with it, and emails can change over time. So "username == email" is fine as long as the concept of a username mutating is fine.

I don't see a problem, it just means you can login with multiple emails then. They're still unique to you. LinkedIn and Facebook and other services already do this.

A username/real name can still be used as the "name" if this is an online community or something similar.

Re: Open Letter to Mozilla: Bring Back Persona

#20
post #2

For more (and better) counter arguments, start with this thread (which was about one particular comparison with Facebook Connect: possibly click to see the parent for context) and then follow my chain of earlier comments I link at the bottom of that one (which were more general, going into the flawed assumptions in Persona about email). https://news.ycombinator.com/item?id=7243172 (By the way, I am going to try to av…

For the abovementioned reason that life is too short, did not read the entire tl;dr thread linked above, but the core objection seems to be that email accounts are fungible. Given the operational experience with Cydia, I will accept at face value that this is a serious real-world problem. What seems wrong to me is throwing up our hands and casting our lot with either of two giant incumbents whose main motivation here is obtaining a constant stream of information on people using their authentication interfaces.

I think it would be highly useful to have a successful open standard for this not controlled by a commercial third party with a financial interest in the implementation.

To the point on account recovery and its pitfalls, any argument that reduces to "System A is better because (in my opinion) those accounts are changed/deleted less often" seems like handwaving. This argument can make any proposal the winner, I myself have no hard data on account churn for any major service, although I accept that email accounts are probably higher turnover than services that introduce user lock-in ... by things like supporting a single sign-on (i.e. Facebook Connect). But WHAT IF an authentication system relied on email accounts, for example. Perhaps users would then be motivated to maintain such accounts for the purpose if it being their auth key.

Finally on the topic of recovery, many services already support the use of a mobile number for this, since these are portable. Implementing this as part of a Persona implementation would seem to address the 'I/someone else threw away my key" problem.

Post reply on HN