Live data from Hacker News

Open Letter to Mozilla: Bring Back Persona

stavros.io

51–60 of 243 posts

Re: Open Letter to Mozilla: Bring Back Persona

#51
> Even if your email provider does end up getting breached, you only need to change one password to be perfectly secure everywhere again.

I liked the article, but this is not true - if a service gives out password reset tokens or log-in-via-emailed-link tokens, a breach of your e-mail will still require a reset on that service. Even in a fully Persona'ified world, such tokens are likely to exist for at least some services.

Re: Open Letter to Mozilla: Bring Back Persona

#52
I created this Persona Advocacy mailing list 11 months ago, but didn't get any traction:

persona.advocacy@librelist.com

http://librelist.com/browser//persona.advocacy/2015/1/24/the...

You can subscribe by sending an email to (first message is ditched):

    persona.advocacy@librelist.com

Re: Open Letter to Mozilla: Bring Back Persona

#53

> I don’t know if something like a Kickstarter campaign to raise some money to pay for engineer time would help sway Mozilla at all, but I’m perfectly happy pledging a few hundred dollars and running the campaign, if necessary. I just really want to see Persona succeed. I mentioned this by email, but I'll repeat it here: I believe in the design behind Persona. I believe a well structured, free authentication provider…

Same here, though Node is not my forte yet.

Re: Open Letter to Mozilla: Bring Back Persona

#55
post #2

For more (and better) counter arguments, start with this thread (which was about one particular comparison with Facebook Connect: possibly click to see the parent for context) and then follow my chain of earlier comments I link at the bottom of that one (which were more general, going into the flawed assumptions in Persona about email). https://news.ycombinator.com/item?id=7243172 (By the way, I am going to try to av…

While I agree that dealing with lost/defunct email addresses and thus accounts can be a challenge there may be other solutions to these (e.g. SMS confirmation, backup pass phrases). In any case it seems we're letting the perfect be the enemy of good with this line of argument. Persona provides significant privacy and perhaps security to alternatives.

Re: Open Letter to Mozilla: Bring Back Persona

#56
post #22

Earlier quoted context omitted.

Functionality such as "forgot password"?

Completely optional. Like HN for example.

So if someone forgets their login details, they're basically screwed? Because I've used some sites like that, and they're a royal pain whenever something goes wrong. For example, TV Tropes didn't used to have a password reset, so every time something went wrong, you'd pretty much have to either register a new account or bug someone on the forums about it.

Same with another site I was on, except the usual solution was seemingly 'find one of the staff on another site they're a member of and send them a message there'. Made for a nice security hole too, since people could (and did) impersonate others and get given their accounts as a result.

You need some sort of email (or other contact information, like a phone number) simply so people can get their account details back in a semi secure way.

Re: Open Letter to Mozilla: Bring Back Persona

#57

> As security people like to say, “put all your eggs in one basket and stick the basket in Fort Knox” I'm not so sure I want to do that. The point is, even that single Fort Knox can be breached at some point, and if it is, then everything is lost. I agree that nowadays, email is almost unanimously the way to verify a password reset, and hence all your eggs are already in one basket, but shouldn't there be further pro…

> "I agree that nowadays, email is almost unanimously the way to verify a password reset, and hence all your eggs are already in one basket, but shouldn't there be further protections?"

A few of the major webmail providers offer two-factor authentication, so that's one option to enhance protection. Here's some information about how to enable it for Gmail, Hotmail and Yahoo Mail:

https://www.google.com/landing/2step/

http://windows.microsoft.com/en-gb/windows/two-step-verifica...

https://help.yahoo.com/kb/SLN5013.html

Re: Open Letter to Mozilla: Bring Back Persona

#58
As a dev, it was really nice to use Persona and not have to build an authentication system for each project.

Now we use Authentic (https://github.com/davidguttman/authentic). In some ways it's better (e.g. get to control your own UI/UX flows), but it would have been nice to just have Mozilla run/host everything.

Re: Open Letter to Mozilla: Bring Back Persona

#59

The best way to get Persona adopted would be to have someone significant other than Mozilla to adopt it. If IE, Safari, or Chrome had adopted, it would have had a great chance at success.

Just to be clear, Persona works on IE, Safari and Chrome as well. It is not tied to Firefox. You can login to MDN for example using Persona on Chrome if you'd like to.

Re: Open Letter to Mozilla: Bring Back Persona

#60
We've had 10+ years now of failures to build a proper federated authentication system (RIP OpenID). The problem isn't technical, and it's only a little bit product design. The problem is political. The big companies with the influence to support a system like Persona don't want it. Facebook, Google, etc believe they can own identity on the Internet themselves, so they won't support a neutral identity provider. Which is a terrible situation for users.

Mozilla absolutely is the right kind of organization to try to attack this Gordian knot.

Post reply on HN