Live data from Hacker News

Introducing BrowserID: A better way to sign in

identity.mozilla.com

111–120 of 188 posts

Re: Introducing BrowserID: A better way to sign in

#111
post #108

Earlier quoted context omitted.

This. Perhaps ssh+http is the solution.

Where is 'this.' coming from? Coding syntax? I just don't get it. I've seen it in HN comments for a few days now, but I fail to understand how 'this.' relates any new information. Reply indenting already tells me you are referring to an antecedent post. (A specific post in fact.) Am I missing something, or is this just a new web fad I'm not savvy too? (Second option is not entirely unlikely...)

It's just for added emphasis. It's the contraction of roughly "this is the correct answer".

Re: Introducing BrowserID: A better way to sign in

#113
post #108

Earlier quoted context omitted.

Where is 'this.' coming from? Coding syntax? I just don't get it. I've seen it in HN comments for a few days now, but I fail to understand how 'this.' relates any new information. Reply indenting already tells me you are referring to an antecedent post. (A specific post in fact.) Am I missing something, or is this just a new web fad I'm not savvy too? (Second option is not entirely unlikely...)

It's just for added emphasis. It's the contraction of roughly "this is the correct answer".

Thanks for enlightening me =)

Re: Introducing BrowserID: A better way to sign in

#114
post #108

Earlier quoted context omitted.

This. Perhaps ssh+http is the solution.

Where is 'this.' coming from? Coding syntax? I just don't get it. I've seen it in HN comments for a few days now, but I fail to understand how 'this.' relates any new information. Reply indenting already tells me you are referring to an antecedent post. (A specific post in fact.) Am I missing something, or is this just a new web fad I'm not savvy too? (Second option is not entirely unlikely...)

It is popular on sites like reddit. It basically means "I agree".

Re: Introducing BrowserID: A better way to sign in

#115
post #105

Earlier quoted context omitted.

Have you read the spec? https://wiki.mozilla.org/Labs/Identity/VerifiedEmailProtocol That's essentially what this is... with a verification service and web based UI to help bootstrap it.

A good way to check if does the right thing is to make sure it does not depend on the security of DNS. Is this the case? (I'm still trying to find out.)

BrowserID implements https://wiki.mozilla.org/Labs/Identity/VerifiedEmailProtocol

From that document: "destination.com retrieves Alice's public key from mailhost.com by using a webfinger lookup over SSL."

So it looks to me that the system's security depends on the attacker not having compromised DNS such that the relying party's query of mailhost.com is intercepted. Depending on the implementation doing this "over SSL" provides some additional security over unchecked reliance on DNS, but given how frequently keys roll, it may not be that much in practice.

Re: Introducing BrowserID: A better way to sign in

#116
post #109

Earlier quoted context omitted.

The proposed BrowserID standard specifically suggests that the browser should ask the email provider to validate the email, and only fall back to the usual email-me-a-link validation if the email provider doesn't "natively" support BrowserID. I'd prefer to always go through email-me-a-link verification (ideally with some kind of crypto involved), rather than involving the email provider in any way other than SMTP and…

Can you link me to where you're reading that? I don't see anything like that (but I've only skimmed the documentation).

See the teaser at https://browserid.org/primaries , and the documentation at http://lloyd.io/how-browserid-works .

Re: Introducing BrowserID: A better way to sign in

#117
post #52

They seriously need to work on their communication skills. It took me a good 15min to figure out what this thing actually does. And I'm still not sure I got it right. OpenID failed because it was too complicated for mere mortals. This, I fear, may be too confusing. At least form the way it's presented. After reading the protocol spec, I have a somewhat better understanding of this. If I got this right, this is basica…

Read the "Verified e-mail protocol" thingy instead. The blurb the link on HN points to is indeed completely useless.

They don't verify e-mail ownership through crypto means - they use the fact that e-mail is identity.

Basically, your mailhost (or a proxy, like browserID) holds your public key, while your browser holds your private key. Now, when you authenticate against any BrowserID auth site, you simply sign with your private key and provide the e-mail address. Since the browser stores both, that's a trivial interaction.

The site then verifies your signature with the mail host. (That's where the asymmetric crypto comes in)

At least that's how I understand it - their explanation is indeed a bit cryptic. Hope they clean it up.

Re: Introducing BrowserID: A better way to sign in

#118
post #23

What I'd really want to see is public-key authentication for website. Let me upload my public key when I create an account on a website, and let the browser interact with my ssh-agent to authenticate.

That's in a way what BrowserID is. Except all sites share one public key, and your browser holds the private key. (Thus replacing ssh-agent)

Re: Introducing BrowserID: A better way to sign in

#119

Earlier quoted context omitted.

"decentralization" doesn't mean "forced decentralization". Anyone can register a domain name and have their own email at that domain, so anyone can create an identity. And ignoring the transitional bits in BrowserID, eventually that identity gets controlled entirely by the public/private keys in the user's browser. Or, in other words: if you don't trust Google, don't use gmail; that someone else chooses to do so does…

Sure, I understand that of course. I am just saying that practically speaking this property is not going to matter much in the world where everyone and their dog is on GMail. It is certainly nice to have though.

The last numbers I saw put Gmail at under 10% of email account marketshare. Hotmail and Yahoo both had much bigger shares.

It's difficult to imagine an authentication system that doesn't have some kind of centralized mechanism for making sure identities aren't duplicated. In this case, delegating that to a combination of two existing technologies (DNS for the domain, then email for the username) that are open, well understood and easy to implement seems appropriate.

What's the alternative? Using some kind of pseudo-GUID and then maybe a derivative of the Paxos distributed consensus algorithm to decide if it is to be trusted? I'd imagine there would be a good number of PhDs in that approach before a system like that would be close to being ready for actual implementation.

This system seems just about as decentralized as is practical. If you disagree I'd be very happy to hear alternatives.

Re: Introducing BrowserID: A better way to sign in

#120
post #52

They seriously need to work on their communication skills. It took me a good 15min to figure out what this thing actually does. And I'm still not sure I got it right. OpenID failed because it was too complicated for mere mortals. This, I fear, may be too confusing. At least form the way it's presented. After reading the protocol spec, I have a somewhat better understanding of this. If I got this right, this is basica…

welcometo: http://www.fullmalls.com The website wholesale for many kinds of fashion shoes, like the nike,jordan,prada,, also including the jeans,shirts,bags,hat and the decorations. All the products are free shipping, and the the price is competitive, and also can accept the paypal payment.,after the payment, can ship within short time. free shippingcompetitive priceany size availableaccept the paypal http://www.fullmalls.com

jordan shoes $32nike shox $32Christan Audigier bikini $23 Ed Hardy Bikini $23Smful short_t-shirt_woman $15ed hardy short_tank_woman $16Sandal $32christian loubo utin $80 Sunglass $15 COACH_Necklace $27handbag $33AF tank woman $17puma slipper woman $30

http://www.fullmalls.com

http://www.fullmalls.com

http://www.fullmalls.com

http://www.fullmalls.com

http://www.fullmalls.com

Post reply on HN