Getting providers onboard with this will be the make or break factor. And I'd really like it to succeed.
Announcing the First Beta Release of Persona
171–180 of 207 posts
Re: Announcing the First Beta Release of Persona
#172Earlier quoted context omitted.
>The point is that you'll only ever need one password this will never be true. You'll only ever need one password for mozilla persona . The user expectation will still be one password per site, and allowing sites to brand the box will only make things even more confusing. It needs a stronger mozilla branding, not a stronger client branding.
> this will never be true Primary IdPs host the log in page, not Mozilla... Say Google implements BrowserID for Gmail. The user will see the same Gmail Auth log in screen they have seen many times before. They only have to remember their gmail password (and any password manager works like it always has on this form). Most likely if your provider is webmail, then you'll already have an active session... so you won't h…
Re: Announcing the First Beta Release of Persona
#173Earlier quoted context omitted.
You could say the same about any traditional username/password signup that sends a confirmation email and allows you to reply to an email to reset your password. Ultimately, that's just relying on the security of your email, too. So while you are correct that Persona doesn't solve that problem, it doesn't make that problem any worse compared to the default option of an email-confirmed username and password.
Yes, most authenticated web services offer a "forgot password" option, and their security is thus tied to your email account. However, each one of these decentralized services on its own is not as valuable as the entire ecosystem of Persona-enabled sites will be. That is, the Persona "forgot password" is a single point of failure which, if compromised, can provide access to a whole ecosystem of sites. And it will be…
Maybe it would help if we considered two hypothetical scenarios. A: Your email is compromised, and you're registered on 15 websites with that email, each of which has a "forgot password" option. B: Your email is compromised, and you've used Persona to sign into 15 websites. In what concrete, practical way is B a more damaging situation than A?
Re: Announcing the First Beta Release of Persona
#174Earlier quoted context omitted.
Persona, the protocol, doesn't actually rely on your email account's password. It uses the domain from your email account to figure out how to authenticate you; if you want to use some other way than via your email, that's fine.
That's correct. However, the security of any Persona-enabled site is tied to your email account's security through Persona "forgot password". This is my concern; a compromised email account means a compromise of your account on every Persona-enabled site.
That’s just how their fallback provider works. BrowserID — the protocol — does not rely on email in any way. There’s no guarantee that if you have valid assertion for joe@dns.tld there’s also an email account by that name.
Re: Announcing the First Beta Release of Persona
#175Earlier quoted context omitted.
Yes, most authenticated web services offer a "forgot password" option, and their security is thus tied to your email account. However, each one of these decentralized services on its own is not as valuable as the entire ecosystem of Persona-enabled sites will be. That is, the Persona "forgot password" is a single point of failure which, if compromised, can provide access to a whole ecosystem of sites. And it will be…
I'm still not seeing a distinction. Your email account is already a single point of failure for every account registered with that email that has a "forgot password" feature. Maybe it would help if we considered two hypothetical scenarios. A: Your email is compromised, and you're registered on 15 websites with that email, each of which has a "forgot password" option. B: Your email is compromised, and you've used Pers…
1) Fight to get your email account back
2) Visit each and every site and manually recover your account
Re: Announcing the First Beta Release of Persona
#176Earlier quoted context omitted.
I was referring to LastPass's Chrome extension specifically, not Persona's UX. Sorry for the confusion.
Can you be more specific as to how you find the LastPass UX lacking? Getting UX right is a priority for LastPass too!
- Completely non-standard menu behaviour and appearance - I to this day can not associate the shortcut icons for copy/edit etc. with the password. Maybe that's just m.. - The one single function I use the most often is "generate password", and it's hidden one menu down from the root. - The second most frequently used function for me is to view the password, when I need to enter it somewhere where I haven't got Lastpass installed (on another device, so copy/past isn't sufficient), yet that requires me to click on the site, "edit" and "show password".
Re: Announcing the First Beta Release of Persona
#177My major concern with this, beside the eggs-in-one-basket issue, is that this places even more value on my email account. Years ago, my email account was simply used for exchanging short pieces of text with acquaintances and companies. Now it's the central key to all my authentication sessions and finances, and therefore presents a huge target for attackers. I've been looking for ways to reduce the risk associated wi…
People simply need to be very very careful about protecting their email account. Use two factor authentication, use a PIN on your smartphone, don't type your email address password on random internet cafe computers, etc.
Re: Announcing the First Beta Release of Persona
#178My major concern with this, beside the eggs-in-one-basket issue, is that this places even more value on my email account. Years ago, my email account was simply used for exchanging short pieces of text with acquaintances and companies. Now it's the central key to all my authentication sessions and finances, and therefore presents a huge target for attackers. I've been looking for ways to reduce the risk associated wi…
You could say the same about any traditional username/password signup that sends a confirmation email and allows you to reply to an email to reset your password. Ultimately, that's just relying on the security of your email, too. So while you are correct that Persona doesn't solve that problem, it doesn't make that problem any worse compared to the default option of an email-confirmed username and password.
You would get a random code or several codes you print out and put into a safe place. If you ever forgot your password, you would dig it our and supply to the website to trigger a reset (which could include or not include email-based verification). The codes would only be usable for passwords resets.