Live data from Hacker News

Announcing the First Beta Release of Persona

identity.mozilla.com

171–180 of 207 posts

Re: Announcing the First Beta Release of Persona

#172
post #156

Earlier quoted context omitted.

>The point is that you'll only ever need one password this will never be true. You'll only ever need one password for mozilla persona . The user expectation will still be one password per site, and allowing sites to brand the box will only make things even more confusing. It needs a stronger mozilla branding, not a stronger client branding.

> this will never be true Primary IdPs host the log in page, not Mozilla... Say Google implements BrowserID for Gmail. The user will see the same Gmail Auth log in screen they have seen many times before. They only have to remember their gmail password (and any password manager works like it always has on this form). Most likely if your provider is webmail, then you'll already have an active session... so you won't h…

Yes... assuming that every site on the internet implements this system. which will never happen.

Re: Announcing the First Beta Release of Persona

#173
post #159
post #65

Earlier quoted context omitted.

You could say the same about any traditional username/password signup that sends a confirmation email and allows you to reply to an email to reset your password. Ultimately, that's just relying on the security of your email, too. So while you are correct that Persona doesn't solve that problem, it doesn't make that problem any worse compared to the default option of an email-confirmed username and password.

Yes, most authenticated web services offer a "forgot password" option, and their security is thus tied to your email account. However, each one of these decentralized services on its own is not as valuable as the entire ecosystem of Persona-enabled sites will be. That is, the Persona "forgot password" is a single point of failure which, if compromised, can provide access to a whole ecosystem of sites. And it will be…

I'm still not seeing a distinction. Your email account is already a single point of failure for every account registered with that email that has a "forgot password" feature.

Maybe it would help if we considered two hypothetical scenarios. A: Your email is compromised, and you're registered on 15 websites with that email, each of which has a "forgot password" option. B: Your email is compromised, and you've used Persona to sign into 15 websites. In what concrete, practical way is B a more damaging situation than A?

Re: Announcing the First Beta Release of Persona

#174
post #160

Earlier quoted context omitted.

Persona, the protocol, doesn't actually rely on your email account's password. It uses the domain from your email account to figure out how to authenticate you; if you want to use some other way than via your email, that's fine.

That's correct. However, the security of any Persona-enabled site is tied to your email account's security through Persona "forgot password". This is my concern; a compromised email account means a compromise of your account on every Persona-enabled site.

> … through Persona "forgot password".

That’s just how their fallback provider works. BrowserID — the protocol — does not rely on email in any way. There’s no guarantee that if you have valid assertion for joe@dns.tld there’s also an email account by that name.

Re: Announcing the First Beta Release of Persona

#175
post #173
post #159

Earlier quoted context omitted.

Yes, most authenticated web services offer a "forgot password" option, and their security is thus tied to your email account. However, each one of these decentralized services on its own is not as valuable as the entire ecosystem of Persona-enabled sites will be. That is, the Persona "forgot password" is a single point of failure which, if compromised, can provide access to a whole ecosystem of sites. And it will be…

I'm still not seeing a distinction. Your email account is already a single point of failure for every account registered with that email that has a "forgot password" feature. Maybe it would help if we considered two hypothetical scenarios. A: Your email is compromised, and you're registered on 15 websites with that email, each of which has a "forgot password" option. B: Your email is compromised, and you've used Pers…

Great point! And the recovery process is much easier in the Persona case... because you only have to fight to get back your Persona account. Today you'll have to

1) Fight to get your email account back

2) Visit each and every site and manually recover your account

Re: Announcing the First Beta Release of Persona

#176
post #165

Earlier quoted context omitted.

I was referring to LastPass's Chrome extension specifically, not Persona's UX. Sorry for the confusion.

Can you be more specific as to how you find the LastPass UX lacking? Getting UX right is a priority for LastPass too!

Another LastPass user here. The two big obvious ones:

- Completely non-standard menu behaviour and appearance - I to this day can not associate the shortcut icons for copy/edit etc. with the password. Maybe that's just m.. - The one single function I use the most often is "generate password", and it's hidden one menu down from the root. - The second most frequently used function for me is to view the password, when I need to enter it somewhere where I haven't got Lastpass installed (on another device, so copy/past isn't sufficient), yet that requires me to click on the site, "edit" and "show password".

Re: Announcing the First Beta Release of Persona

#177
post #62

My major concern with this, beside the eggs-in-one-basket issue, is that this places even more value on my email account. Years ago, my email account was simply used for exchanging short pieces of text with acquaintances and companies. Now it's the central key to all my authentication sessions and finances, and therefore presents a huge target for attackers. I've been looking for ways to reduce the risk associated wi…

People simply need to be very very careful about protecting their email account. Use two factor authentication, use a PIN on your smartphone, don't type your email address password on random internet cafe computers, etc.

No. Websites should stop outsourcing their security to third parties they know nothing about (such as email providers). It's not just a matter of immediate security, but overall architecture quality as well. Having your entire digital life depend on an account that, for most people, is hosted by a third party, for free and without any guarantees is dumb. Email simply wasn't mean for that kind of use.

Re: Announcing the First Beta Release of Persona

#178
post #65
post #62

My major concern with this, beside the eggs-in-one-basket issue, is that this places even more value on my email account. Years ago, my email account was simply used for exchanging short pieces of text with acquaintances and companies. Now it's the central key to all my authentication sessions and finances, and therefore presents a huge target for attackers. I've been looking for ways to reduce the risk associated wi…

You could say the same about any traditional username/password signup that sends a confirmation email and allows you to reply to an email to reset your password. Ultimately, that's just relying on the security of your email, too. So while you are correct that Persona doesn't solve that problem, it doesn't make that problem any worse compared to the default option of an email-confirmed username and password.

Considering that it's a new protocol, why not try to solve that old problem? At the very least, they could allow you to disable email-based password reset in favor of printed code. That would be a smart thing to do.

You would get a random code or several codes you print out and put into a safe place. If you ever forgot your password, you would dig it our and supply to the website to trigger a reset (which could include or not include email-based verification). The codes would only be usable for passwords resets.

Post reply on HN