Live data from Hacker News

Open Letter to Mozilla: Bring Back Persona

stavros.io

121–130 of 243 posts

Re: Open Letter to Mozilla: Bring Back Persona

#121
post #82

Disclaimer: I work for Mozilla, I maintain django-browserid (and StravosK is a valued contributor many sites. This is all just my own personal opinion. I was very bullish on Persona early on, but the fact of the matter is, we failed . And not just because (as I feel is being implied) some higher up suddenly came over and asked for an unreasonable amount of adoption for a revolutionary product. We failed for a thousan…

So, perhaps a different question - Can Mozilla host / bless the mailing list / forum where these successors to persona are discussed, built with volunteers and tried out?

Re: Open Letter to Mozilla: Bring Back Persona

#122
post #108
post #105

Earlier quoted context omitted.

Because i'd love for my reddit username to be my email when i decide to play devils advocate, and campaign for Trump.

Pretty easy to register TrumpRulez2016@yahoo.com for that purpose.

Registering Yahoo addresses is actually anything but "simple" anymore.

Re: Open Letter to Mozilla: Bring Back Persona

#123
post #85
post #22

Earlier quoted context omitted.

Completely optional. Like HN for example.

I thought so too. But then people started forgetting their passwords, so i made email mandatory. People will rarely write down/take note of their password to a website that they "just want to check out".

If they just want to check your website out, why are you forcing them to choose a password anyway?

Re: Open Letter to Mozilla: Bring Back Persona

#124
I don't really see the point in this and this is why: let's say Persona won and all the big ones switched to it (Facebook, Google, Twitter etc.) by becoming providers. Most people would still be using their Facebook, Google or Twitter persona anyway (except for a few privacy sensitive users who don't like SaaS anyway because it's bad for privacy according to them). So we would have a situation that would be de facto very similar to what we have now (3 sigin buttons for facebook, google and twitter) and then an extra one for people using their own hosted provider. This is what happened with OpenID, problem was that supporting people using their own providers became a nightmare as these providers went down or had some incompatibilities. People were just angry they couldn't sign in with their old providers, many of theme may have not even known they were using custom providers or what providers are and the other half would be privacy nerds who enjoy complaining every time their custom provider stops being fully compatible. For app owners, it would just be a big waste of time and resources supporting these users.

Re: Open Letter to Mozilla: Bring Back Persona

#125

Earlier quoted context omitted.

Side note: usernames should just be emails these days, they're unique and save all the effort of needing another made up name.

What's the benefit? And, more than this, why do I must provide anyone my mail address? Why do I have to provide it at all? I understand and I'll provide my email address, my JID, my phone number and whatever else I'm willing to provide, if I want someone to contact me. But contact details are technically completely unnecessary to just have an account.

I agree. We're doing this wrong. Airport "free" WiFi wanting to know my date of birth, and cranky weird crap like that.

Re: Open Letter to Mozilla: Bring Back Persona

#126
post #115
post #5

I hate that the best user experience for logins is "Login with facebook" or "Login with Google". I don't want to impose that privacy failure on my users, but I also don't want to impose the annoyance that is "Sign up with a username, email address, and password". Offering all of the options is also a compromise that complicates the user experience. Now, here's the sad thing, for me: I didn't even know Persona existed…

> I don't want to impose that privacy failure on my users, but I also don't want to impose the annoyance that is "Sign up with a username, email address, and password". Why not just 'log in with email address'? The user provides his email address; you send him an email with a URL of the form http://www.invalid/path/to/resource?access_token=aSBkb25lIGF... (where aSBkb25lIGF1dGhlbnRpY2F0ZWQgdGhpcw is a cryptographicall…

However, this method can't really be used everywhere -- not all emails are encrypted up to the point where the recipient reads them.

Re: Open Letter to Mozilla: Bring Back Persona

#127
post #115
post #5

I hate that the best user experience for logins is "Login with facebook" or "Login with Google". I don't want to impose that privacy failure on my users, but I also don't want to impose the annoyance that is "Sign up with a username, email address, and password". Offering all of the options is also a compromise that complicates the user experience. Now, here's the sad thing, for me: I didn't even know Persona existed…

> I don't want to impose that privacy failure on my users, but I also don't want to impose the annoyance that is "Sign up with a username, email address, and password". Why not just 'log in with email address'? The user provides his email address; you send him an email with a URL of the form http://www.invalid/path/to/resource?access_token=aSBkb25lIGF... (where aSBkb25lIGF1dGhlbnRpY2F0ZWQgdGhpcw is a cryptographicall…

This is essentially the same thing as having your password emailed to you and is insecure for all the same reasons. Youre putting the responsibility of security on the email provider, which you can't control.

Re: Open Letter to Mozilla: Bring Back Persona

#128
post #115
post #5

I hate that the best user experience for logins is "Login with facebook" or "Login with Google". I don't want to impose that privacy failure on my users, but I also don't want to impose the annoyance that is "Sign up with a username, email address, and password". Offering all of the options is also a compromise that complicates the user experience. Now, here's the sad thing, for me: I didn't even know Persona existed…

> I don't want to impose that privacy failure on my users, but I also don't want to impose the annoyance that is "Sign up with a username, email address, and password". Why not just 'log in with email address'? The user provides his email address; you send him an email with a URL of the form http://www.invalid/path/to/resource?access_token=aSBkb25lIGF... (where aSBkb25lIGF1dGhlbnRpY2F0ZWQgdGhpcw is a cryptographicall…

"Why not just...?"

I enjoy that you offer up a quite complex, confusing, often insecure, and error-prone methodology with this phrase.

Re: Open Letter to Mozilla: Bring Back Persona

#129
post #25
post #7

I find Keepass and/or Lastpass are better solutions - you can have different logins for different sites, generate truly strong random passwords and login with two clicks in any modern browser. I don't want Google (or God forbid, Facebook) knowing what sites I login to and part of my credentials, and I don't want websites to know my email address. I know you say they don't have this information, but it's not hard to g…

> Google Web History already creeps me out :-) You know that you can turn off most of their tracking by doing a privacy checkup? I can't guarantee that they don't know a lot about me and that they're still not tracking me, but I can guarantee you that my Google history is completely blank.

Do you actually believe this accomplishes anything… This data is still in their server logs[1] (and streamed directly to NSA).

USE TOR BROWSER FOR BROWSING. DON’T STAY LOGGED INTO GOOGLE. Anything less is just a waste of time.

And seriously, Tor in 2015 is fast enough for 1080p h.264, there’s really no excuse.

[1] https://nakedsecurity.sophos.com/2011/10/20/law-student-trig...

Re: Open Letter to Mozilla: Bring Back Persona

#130
post #125

Earlier quoted context omitted.

What's the benefit? And, more than this, why do I must provide anyone my mail address? Why do I have to provide it at all? I understand and I'll provide my email address, my JID, my phone number and whatever else I'm willing to provide, if I want someone to contact me. But contact details are technically completely unnecessary to just have an account.

I agree. We're doing this wrong. Airport "free" WiFi wanting to know my date of birth, and cranky weird crap like that.

And im just going to lie anyway. How many people tell the truth on those?
Post reply on HN