Introducing BrowserID: A better way to sign in
161–170 of 188 posts
Re: Introducing BrowserID: A better way to sign in
#162Earlier quoted context omitted.
Wow, I had exactly the opposite experience. Tons of thoughts popped into mind as I watched. If my brain had a replay button, it would say: * Ok, what if I have multiple accounts? Ahh, nice. * Hmm it would be cool if it worked like LastPass, where you get great security and only one password to remem... ha, nice, it's very similar! * Email verification? ....yep, check. * Can you lock the browser so that nobody can jus…
Exactly, I think most users of LastPass or 1Password had the same thoughts. The question I do have: why would I use this over something like LastPass which already has plugins for every browser and device most people will ever care about?
Re: Introducing BrowserID: A better way to sign in
#163Thought that popped into my head. Instead of having separate passwords for different sites, now you are trusting your email provider to be absolutely secure (with that one ultra-secure password you are using, right?). So if a BrowserID user were to ever get their email service compromised, it's keys to the kingdom. IMO, I think this needs a rethink.
The idea is that you would use this in situations where you currently would offer a "reset password via email" option - since this means you already treats control of the email address as identity.
But anyways, my impression from reading the page was this is not just used as a password reset scenario but as a general login method.
Which if you agree with, leads us back to the scenario where authentication & authorization lies solely with the email account, which if compromised is the single point of failure.
I would appreciate it if someone were to help point out what flaws there in this line of thought rather than a straight downvote with no explanation.
Re: Introducing BrowserID: A better way to sign in
#164Earlier quoted context omitted.
The last numbers I saw put Gmail at under 10% of email account marketshare. Hotmail and Yahoo both had much bigger shares. It's difficult to imagine an authentication system that doesn't have some kind of centralized mechanism for making sure identities aren't duplicated. In this case, delegating that to a combination of two existing technologies (DNS for the domain, then email for the username) that are open, well u…
Zooko's triangle[1] in action: A BrowserID (like an email address) is memorable and secure, but not decentralized (it's centralized in DNS). A cryptographic key is decentralized and secure, but not memorable. Systems that are memorable and decentralized, but not secure, don't address these use cases at all. (And then there's Namecoin[2], which is a fascinating development, but not likely to see broad adoption in the…
Re: Introducing BrowserID: A better way to sign in
#165Re: Introducing BrowserID: A better way to sign in
#166Am I the only one who kind of wishes we never went down this "let's fix authentication!" rabbit hole? It feels like we've just replaced one problem with another. Now, instead of simply having to remember what username/password combination I used, I have to remember which (if any) OpenID provider I used, how much information about myself does said provider expose, and how to merge my accounts when I inevitably end up…
Did you read the article ? This is an attempt to fix all those issues you list.
At least with normal un/pw you need to request a password reset from the website.
I don't think we should be tying logins to email.
Re: Introducing BrowserID: A better way to sign in
#167Somehow I find WebID ( http://www.w3.org/wiki/WebID ) more appealing. There are already countries that give their citizens SSL client certs.
Re: Introducing BrowserID: A better way to sign in
#168What I'd really want to see is public-key authentication for website. Let me upload my public key when I create an account on a website, and let the browser interact with my ssh-agent to authenticate.
It's discontinued though unfortunately. Although there are still people out there making it work with newer versions of Firefox: https://grepular.com/FireGPG_on_Firefox_5
Re: Introducing BrowserID: A better way to sign in
#169Earlier quoted context omitted.
The idea is that you would use this in situations where you currently would offer a "reset password via email" option - since this means you already treats control of the email address as identity.
Wondering why I was downvoted for pointing this out. But anyways, my impression from reading the page was this is not just used as a password reset scenario but as a general login method. Which if you agree with, leads us back to the scenario where authentication & authorization lies solely with the email account, which if compromised is the single point of failure. I would appreciate it if someone were to help point…
In effect, any site that offers a password reset via email is already using your email as your identity.
Re: Introducing BrowserID: A better way to sign in
#170BrowserID is a good first step, but ultimately as a website owner I'd much rather authenticate with Twitter/Facebook, since it makes it easier for me to figure out who the user is/ask them to share with friends. Identity is cool, but Facebook is winning the 3rd party connect game right now because it offers websites syndication, which is more valuable than just authentication. I'd love to see a BrowserID that can als…
I do not trust either of these companies, or have a strong attachment to them.
If they want to support BrowserID then they can - as username@facebook.com or username@twitter.com