I liked the article, but this is not true - if a service gives out password reset tokens or log-in-via-emailed-link tokens, a breach of your e-mail will still require a reset on that service. Even in a fully Persona'ified world, such tokens are likely to exist for at least some services.
Open Letter to Mozilla: Bring Back Persona
51–60 of 243 posts
Re: Open Letter to Mozilla: Bring Back Persona
#52persona.advocacy@librelist.com
http://librelist.com/browser//persona.advocacy/2015/1/24/the...
You can subscribe by sending an email to (first message is ditched):
persona.advocacy@librelist.comRe: Open Letter to Mozilla: Bring Back Persona
#53> I don’t know if something like a Kickstarter campaign to raise some money to pay for engineer time would help sway Mozilla at all, but I’m perfectly happy pledging a few hundred dollars and running the campaign, if necessary. I just really want to see Persona succeed. I mentioned this by email, but I'll repeat it here: I believe in the design behind Persona. I believe a well structured, free authentication provider…
Re: Open Letter to Mozilla: Bring Back Persona
#54Re: Open Letter to Mozilla: Bring Back Persona
#55For more (and better) counter arguments, start with this thread (which was about one particular comparison with Facebook Connect: possibly click to see the parent for context) and then follow my chain of earlier comments I link at the bottom of that one (which were more general, going into the flawed assumptions in Persona about email). https://news.ycombinator.com/item?id=7243172 (By the way, I am going to try to av…
Re: Open Letter to Mozilla: Bring Back Persona
#56Earlier quoted context omitted.
Functionality such as "forgot password"?
Completely optional. Like HN for example.
Same with another site I was on, except the usual solution was seemingly 'find one of the staff on another site they're a member of and send them a message there'. Made for a nice security hole too, since people could (and did) impersonate others and get given their accounts as a result.
You need some sort of email (or other contact information, like a phone number) simply so people can get their account details back in a semi secure way.
Re: Open Letter to Mozilla: Bring Back Persona
#57> As security people like to say, “put all your eggs in one basket and stick the basket in Fort Knox” I'm not so sure I want to do that. The point is, even that single Fort Knox can be breached at some point, and if it is, then everything is lost. I agree that nowadays, email is almost unanimously the way to verify a password reset, and hence all your eggs are already in one basket, but shouldn't there be further pro…
A few of the major webmail providers offer two-factor authentication, so that's one option to enhance protection. Here's some information about how to enable it for Gmail, Hotmail and Yahoo Mail:
https://www.google.com/landing/2step/
http://windows.microsoft.com/en-gb/windows/two-step-verifica...
Re: Open Letter to Mozilla: Bring Back Persona
#58Now we use Authentic (https://github.com/davidguttman/authentic). In some ways it's better (e.g. get to control your own UI/UX flows), but it would have been nice to just have Mozilla run/host everything.
Re: Open Letter to Mozilla: Bring Back Persona
#59The best way to get Persona adopted would be to have someone significant other than Mozilla to adopt it. If IE, Safari, or Chrome had adopted, it would have had a great chance at success.
Re: Open Letter to Mozilla: Bring Back Persona
#60Mozilla absolutely is the right kind of organization to try to attack this Gordian knot.