Live data from Hacker News

Mozilla Persona and Surveillance

identity.mozilla.com

31–40 of 59 posts

Re: Mozilla Persona and Surveillance

#31

Earlier quoted context omitted.

The last bit here is a reach. For starters, Persona uses SSL, so it's encrypted. But more broadly, if you're going to use centralized, third-party authentication mechanism you could do far, far worse than Persona. I'd go so far as to say if your site is implementing its own authentication system, you could do yourself even more damage with a poor implementation. Your critique seems to missed an important part about P…

I know nothing about Persona. I have never used, and I have not read anything about it. But that much is clear to me: the communication between you and the Persona provider can happen very much over an encrypted channel, but the data in the Provider is not encrypted with a key which you only know. The Persona provider has the data in the open (except passwords, which are hashed) This whole fiasco has shown a weakness…

Dude, what the hell are you talking about?

The only thing those in power would find out by looking at Mozilla's servers in charge with Persona authentication would be your freaking email address and that's it. This is by design.

Re: Mozilla Persona and Surveillance

#32

Earlier quoted context omitted.

I know nothing about Persona. I have never used, and I have not read anything about it. But that much is clear to me: the communication between you and the Persona provider can happen very much over an encrypted channel, but the data in the Provider is not encrypted with a key which you only know. The Persona provider has the data in the open (except passwords, which are hashed) This whole fiasco has shown a weakness…

Dude, what the hell are you talking about? The only thing those in power would find out by looking at Mozilla's servers in charge with Persona authentication would be your freaking email address and that's it. This is by design.

"It’s also worth pointing out that we do take certain technical measures to limit the data we collect. We’ve designed Persona so that the identity provider – including the fallback Identity Provider that we run – does not learn your browsing history."

That does not say "we only store your email address". It also does not say they are storing more than that, either. In any case, the data is not encrypted, so my argument stands.

Re: Mozilla Persona and Surveillance

#33
post #28
post #25

Earlier quoted context omitted.

Decentralisation can happen gradually. By using a browserId enabled user agent/browser and an email provider who has implemented the browserId -protocol you already have a fully decentralised Persona experience.

My problem is with the "email provider" part. In the real world, it just means Google, Yahoo, Microsoft, and handful of firms (like Rackspace) that provide hosted email solutions for a fee. You might call it "decentralized", but I'd call it "mostly centralized".

It's still way, way better than "Log in with Facebook" and has the potential to get even better over time.

Re: Mozilla Persona and Surveillance

#34
post #28

Earlier quoted context omitted.

My problem is with the "email provider" part. In the real world, it just means Google, Yahoo, Microsoft, and handful of firms (like Rackspace) that provide hosted email solutions for a fee. You might call it "decentralized", but I'd call it "mostly centralized".

It's still way, way better than "Log in with Facebook" and has the potential to get even better over time.

Of course it is, but it still ain't anything close to optimal.

Re: Mozilla Persona and Surveillance

#35

The most important line for me from the blog post was Third, we’d rather not engage in an arms-race with US government agencies. We’d rather focus on efforts to change the Law to respect user data wherever it lives. This effectively tells a lot about Mozilla's intent.

how do you know mozilla was not forced by US to post just that? and they cant tell you they have been forced to do this. This simple fact basically destroys persona imho.

Re: Mozilla Persona and Surveillance

#36

The statement that Mozilla should have issued: "Some have claimed that we should move Mozilla out of the US. Unfortunately, for reasons of connectivity, workforce, ties to US market, legal issues and restructuring costs we are not able to do that. Current (recurring) developments in the US have shown that our government can not be trusted. No amount of legislation is going to achieve a fully accountable government. B…

Plus: "Some have called on us to move Persona servers outside the US..." But: "We’d rather focus on efforts to change the Law to respect user data wherever it lives." What?! Who says it's an either-or question? IT'S NOT! IT HAS NEVER BEEN! ANY and ALL means must be used, given the gravity of the situation!

The blog post doesn't say it's an either-or question. It says that, given that Mozilla has limited resources, we think it is more effective to focus those resources on changing the law to benefit the user rather than trying to fix just Persona by moving it to another country.

If we had unlimited resources than we'd be able to do both, but the post goes on to explain why that wouldn't be effective anyway.

(Disclaimer: I work for Mozilla in a different department than the Persona team.)

Re: Mozilla Persona and Surveillance

#37
It seems to me as though an interim solution would be to partner with organizations in other countries to set up Persona fallbacks there. Key to this is that it would need to be a partnership with an entity local to the nation where the server is stored: Mozilla should not run these services itself, for the reasons listed in Mozilla's own post.

Has this option been explored, or at least considered?

Re: Mozilla Persona and Surveillance

#38
post #26

One great thing about Persona is that it doesn't have to get involved every time I log into some website. The keys can be cached, so Persona doesn't need to know which websites I visit the most frequently, how long I spend on each site, which pages I read, etc. Persona just provides the identity and stops there. In that sense, Persona's very design makes it an unattractive target of surveillance. Not much data there.…

Unless I'm mistaken[1], right now the popup that has multiple emails in it is the part that will eventually become native to the browser itself, so no service should have access to that list of multiple emails.

Each of those emails is instead tied to an identity provider: for example, you might have a GMail address that uses Google as the IdP, while a Yahoo one would use Yahoo as the IdP. But Google and Yahoo don't actually know that you're using multiple emails to login to stuff, they only deal with the emails you register with them.

What happens right now is that Mozilla Persona hosts the JS-powered popup that lets you choose between emails, so we end up with that info. This is for use in the short-term and for older browsers, but long term I think it will shift to client-side only.

[1] I work for Mozilla, but not on the Persona project, so there is a chance that I'm completely wrong. Doh!

Re: Mozilla Persona and Surveillance

#39

Earlier quoted context omitted.

Dude, what the hell are you talking about? The only thing those in power would find out by looking at Mozilla's servers in charge with Persona authentication would be your freaking email address and that's it. This is by design.

"It’s also worth pointing out that we do take certain technical measures to limit the data we collect. We’ve designed Persona so that the identity provider – including the fallback Identity Provider that we run – does not learn your browsing history." That does not say "we only store your email address". It also does not say they are storing more than that, either. In any case, the data is not encrypted, so my argume…

You should read up on what Persona is before making judgments about it. Just a general guideline for reasonable discourse.

Re: Mozilla Persona and Surveillance

#40
post #38
post #26

One great thing about Persona is that it doesn't have to get involved every time I log into some website. The keys can be cached, so Persona doesn't need to know which websites I visit the most frequently, how long I spend on each site, which pages I read, etc. Persona just provides the identity and stops there. In that sense, Persona's very design makes it an unattractive target of surveillance. Not much data there.…

Unless I'm mistaken[1], right now the popup that has multiple emails in it is the part that will eventually become native to the browser itself, so no service should have access to that list of multiple emails. Each of those emails is instead tied to an identity provider: for example, you might have a GMail address that uses Google as the IdP, while a Yahoo one would use Yahoo as the IdP. But Google and Yahoo don't a…

When I log into persona.org, it seems to allow me to remove my (currently only) email address by clicking the first blue "Edit" button and then clicking "Remove" next to my email address. So I assumed that, in the future, I might also be able to add email addresses. Sorry if I was wrong about this.
Post reply on HN