Live data from Hacker News

Mozilla Persona and Surveillance

identity.mozilla.com

41–50 of 59 posts

Re: Mozilla Persona and Surveillance

#41
post #8

Earlier quoted context omitted.

> "Third, we’d rather not engage in an arms-race with US government agencies." > Read: we are afraid to lead here, because backlash from the government (and the public?) could be too damaging for Mozilla. I read "This is a race we'll probably not win and even if we do, we'd have a lot of power tied up there. But we can win by just changing the rules, so let's do that."

The US has been changing the rules since decades. The shadow government has adapted to those changes, becoming more and more powerful with each change. The US will pass a couple of "government openness" laws in the coming months (years?). The shadow government will laugh at that, move operation proceedings to the new release, and increase the broadness of surveillance, thanks to improvements in technology. The only w…

Note that moving the servers from the US would not be sufficient - you'd have to move the domain to a TLD not controlled by the US or any other entity that they can influence. You'd have to host with a provider independent enough etc.

Thus, the stated goal of persona is to remove the need for a centralized auth provider - thus sidestepping the problem of where those centralized servers are located. That's why they don't want to engage in a whack-a-mole game with the US government.

Re: Mozilla Persona and Surveillance

#42
post #36

Earlier quoted context omitted.

Plus: "Some have called on us to move Persona servers outside the US..." But: "We’d rather focus on efforts to change the Law to respect user data wherever it lives." What?! Who says it's an either-or question? IT'S NOT! IT HAS NEVER BEEN! ANY and ALL means must be used, given the gravity of the situation!

The blog post doesn't say it's an either-or question. It says that, given that Mozilla has limited resources, we think it is more effective to focus those resources on changing the law to benefit the user rather than trying to fix just Persona by moving it to another country. If we had unlimited resources than we'd be able to do both, but the post goes on to explain why that wouldn't be effective anyway. (Disclaimer:…

Honest question: why the wishful thinking? Why not tell it like it is? What is the potential damage that Mozilla could suffer by clearly stating that it is impossible and it will be impossible to guarantee that the government will not be monitoring all online activity? We know that the shadow-government is very good at:

1) Spying its citizens, using legal or illegal methods.

2) Cover up those operations with the use of force (indoctrination, legal threats, imprisonments, ...)

3) Change operation procedures whenever a martyr leaks the modus operandi, and improve the sealing of those activities.

This has been going on for decades. They have been iterating on this for a long time and we can assume that the shadow-government is very competent at it, so it will be impossible to control it. It is not possible to reign on the secret machine anymore.

The latest improvements on the spying machine are:

1) Better understanding of the whistleblower phenomenon: how to better indoctrinate workers so that they are less likely to talk, how to assassinate the character by using the media, how to create an example by using the full force of the law (whatever that means in this context) to make the possibility of leakages in the future less likely, how to put pressure in other governments to aid in the prosecution of whistleblowers. They have had lately several high-profile cases (Manning, Assange) for testing their machinery, and it is working perfectly.

2) Coerce companies into collaboration, and at the same time legally forbid them to neither confirm nor deny participation. I must say that this is simply a work of genius.

Mozilla could at least openly recognize this fact, as long as this is still a legal thing to do. The next iteration of the spying machine will maybe not even allow us to have this conversation. Who does feel safe talking about this things anymore? Not me, for sure.

Mozilla could still in good faith recommend Persona, while clearly stating that they are in no position to make any guarantee whatsoever about possible monitoring activities.

Re: Mozilla Persona and Surveillance

#43

Earlier quoted context omitted.

"It’s also worth pointing out that we do take certain technical measures to limit the data we collect. We’ve designed Persona so that the identity provider – including the fallback Identity Provider that we run – does not learn your browsing history." That does not say "we only store your email address". It also does not say they are storing more than that, either. In any case, the data is not encrypted, so my argume…

You should read up on what Persona is before making judgments about it. Just a general guideline for reasonable discourse.

Here: http://www.mozilla.org/en-US/persona/

"Many sign-in systems carry your profile data with them; some even share that info with other sites and social networks. We believe you should control how your personal information is shared. Persona lets you get started with just your email address; you can add your profile data later, when and where you think it’s appropriate."

Whatever that "profile data" is, can be requested by the government.

Re: Mozilla Persona and Surveillance

#44

Earlier quoted context omitted.

The US has been changing the rules since decades. The shadow government has adapted to those changes, becoming more and more powerful with each change. The US will pass a couple of "government openness" laws in the coming months (years?). The shadow government will laugh at that, move operation proceedings to the new release, and increase the broadness of surveillance, thanks to improvements in technology. The only w…

Note that moving the servers from the US would not be sufficient - you'd have to move the domain to a TLD not controlled by the US or any other entity that they can influence. You'd have to host with a provider independent enough etc. Thus, the stated goal of persona is to remove the need for a centralized auth provider - thus sidestepping the problem of where those centralized servers are located. That's why they do…

So you are saying that Mozilla can be a trustworthy partner in the development of Persona (since it is opensource, I guess?), but not a trustworthy Persona provider (since they are US based). That sounds reasonable, and Mozilla deserves much credit for that.

Re: Mozilla Persona and Surveillance

#46
post #26

One great thing about Persona is that it doesn't have to get involved every time I log into some website. The keys can be cached, so Persona doesn't need to know which websites I visit the most frequently, how long I spend on each site, which pages I read, etc. Persona just provides the identity and stops there. In that sense, Persona's very design makes it an unattractive target of surveillance. Not much data there.…

I've created something to allow you to easily become your own identity provider here: https://persowna.net/

Given the design of Persona, though, your identity provider can't know which site you're logging into, only that you're logging in to something.

Re: Mozilla Persona and Surveillance

#47
post #40
post #38

Earlier quoted context omitted.

Unless I'm mistaken[1], right now the popup that has multiple emails in it is the part that will eventually become native to the browser itself, so no service should have access to that list of multiple emails. Each of those emails is instead tied to an identity provider: for example, you might have a GMail address that uses Google as the IdP, while a Yahoo one would use Yahoo as the IdP. But Google and Yahoo don't a…

When I log into persona.org, it seems to allow me to remove my (currently only) email address by clicking the first blue "Edit" button and then clicking "Remove" next to my email address. So I assumed that, in the future, I might also be able to add email addresses. Sorry if I was wrong about this.

You can add email addresses now, this is just for the bridge, so it allows you to use alternate addresses to log in with. It's not specific to Persona, it's just how they designed the current bridge (which they aim to phase out in the long run).

Re: Mozilla Persona and Surveillance

#48

Earlier quoted context omitted.

You should read up on what Persona is before making judgments about it. Just a general guideline for reasonable discourse.

Here: http://www.mozilla.org/en-US/persona/ "Many sign-in systems carry your profile data with them; some even share that info with other sites and social networks. We believe you should control how your personal information is shared. Persona lets you get started with just your email address; you can add your profile data later, when and where you think it’s appropriate." Whatever that "profile data" is, can be requ…

The "profile data" that refers to is the profile data you want to add per-site. It's got nothing to do with Persona.

All Persona knows is your email, a password and the fact that you (maybe) want to authenticate at some point (but it doesn't know where, and it can't be sure you're actually trying to authenticate somewhere even).

Re: Mozilla Persona and Surveillance

#49
post #28
post #25

Earlier quoted context omitted.

Decentralisation can happen gradually. By using a browserId enabled user agent/browser and an email provider who has implemented the browserId -protocol you already have a fully decentralised Persona experience.

My problem is with the "email provider" part. In the real world, it just means Google, Yahoo, Microsoft, and handful of firms (like Rackspace) that provide hosted email solutions for a fee. You might call it "decentralized", but I'd call it "mostly centralized".

Eh, so what? The only thing your provider knows is that you're trying to authenticate somewhere, but not where. It's hardly bad.

Re: Mozilla Persona and Surveillance

#50
post #21

Earlier quoted context omitted.

> it can be decentralised Technically, yes. Realistically, highly unlikely. What's going to happen, at best, is that email service providers like Google and Microsoft will begin to support Persona. Either as a replacement for OpenID, or in addition to it. A negligible minority of the human population, such as regular HN readers like you and I, might opt to implement Persona on our own servers, but everyone else will…

Realistically and perhaps sooner than you think They are finishing up the LDAP based provider, once that happens, you could hook it up to most company-wide authentication systems. Once that's working @university.edu and @bigco.com would authenticate directly with the organization. That'll be huge. This is a very very high value feature, I expect it to be the driving force for adoption. One of the big challenges of la…

That's exactly my thinking when creating https://persowna.net/. Providing authentication that hooks up to the corporation's specific system for the entire web is potentially a very big thing.
Post reply on HN