Live data from Hacker News

Mozilla adopts plain-vanilla password sign-in for Firefox sync

news.hitb.org

21–30 of 44 posts

Re: Mozilla adopts plain-vanilla password sign-in for Firefox sync

#22
post #3

I see this as a reaction to the competition they're facing with Google Chrome. With Google Chrome you log into your Google account. email + password and all is good. It's simple , but fundamentally insecure. Google, NSA and whoever else they partner with can poke at all your data without restriction because it is based on a centralized authentication model. Firefox always based its sync on a secure model where no dat…

This isn't really accurate.

The problem with Firefox's current/old sync model is recovery. I.e., users think they're getting their stuff (history, passwords, etc) backed up, but when they lose their device, their data is gone forever, because almost none of them will have bothered to write down the long random string that functioned as their sync key. Also, the pairing was relatively hard to use for "normal" users.

In the newer Firefox Accounts model, yes, Mozilla will use a username/password model for users. However, the password is never sent to Mozilla in the clear, and data is still encrypted with a password-derived key before being sent to Mozilla. However, users can still recover their data because they know (something that can be used to generate) the key used to encrypt their data.

See here for more details: https://github.com/mozilla/fxa-auth-server/wiki/onepw-protoc...

I do think Mozilla would have promoted Sync more if it didn't have the recovery/UX issues I mentioned, so in that sense it might be a response to Google's model, but Mozilla's model still has a very well thought-out privacy strategy.

For those who actually liked the previous random key model + pairing, I think they might reinstate that as an option within the newer protocol/implementation at some point.

Re: Mozilla adopts plain-vanilla password sign-in for Firefox sync

#23
post #3

I see this as a reaction to the competition they're facing with Google Chrome. With Google Chrome you log into your Google account. email + password and all is good. It's simple , but fundamentally insecure. Google, NSA and whoever else they partner with can poke at all your data without restriction because it is based on a centralized authentication model. Firefox always based its sync on a secure model where no dat…

This isn't really accurate. The problem with Firefox's current/old sync model is recovery. I.e., users think they're getting their stuff (history, passwords, etc) backed up, but when they lose their device, their data is gone forever, because almost none of them will have bothered to write down the long random string that functioned as their sync key. Also, the pairing was relatively hard to use for "normal" users. I…

Can you still host your own easily under the new model? That aspect of Firefox Sync was already deemphasized before, and that this is lost is what I fear the most with such changes.

My data silo is a box 80cm to my right. No need to start a new one at Mozilla Inc/Org.

Re: Mozilla adopts plain-vanilla password sign-in for Firefox sync

#24

Will Mozilla be removing the secure sync option or having this one in parallel? I don't use it myself, but it's definitely worrying to see a secure option being potentially removed in favour of plaintext storage on servers outside the user's control.

See my answer here for some answers to your question:

https://news.ycombinator.com/item?id=7169969

Re: Mozilla adopts plain-vanilla password sign-in for Firefox sync

#26
post #18

Earlier quoted context omitted.

Those who would sacrifice privacy for convenience deserve neither.

So you're implying that 99% of humanity will have no privacy nor security?

That appears to be where we are headed.

Re: Mozilla adopts plain-vanilla password sign-in for Firefox sync

#27
post #23

Earlier quoted context omitted.

This isn't really accurate. The problem with Firefox's current/old sync model is recovery. I.e., users think they're getting their stuff (history, passwords, etc) backed up, but when they lose their device, their data is gone forever, because almost none of them will have bothered to write down the long random string that functioned as their sync key. Also, the pairing was relatively hard to use for "normal" users. I…

Can you still host your own easily under the new model? That aspect of Firefox Sync was already deemphasized before, and that this is lost is what I fear the most with such changes. My data silo is a box 80cm to my right. No need to start a new one at Mozilla Inc/Org.

All the software for running a server is open source, I think, so in that sense it should be possible. Whether there will still be enough prefs such that you can get Firefox to sync against a different host, I'm not sure, but it seems likely that that will be possible.

Re: Mozilla adopts plain-vanilla password sign-in for Firefox sync

#28
post #18

Earlier quoted context omitted.

Those who would sacrifice privacy for convenience deserve neither.

So you're implying that 99% of humanity will have no privacy nor security?

Isn't that where we are at right now?

Re: Mozilla adopts plain-vanilla password sign-in for Firefox sync

#29

Will Mozilla be removing the secure sync option or having this one in parallel? I don't use it myself, but it's definitely worrying to see a secure option being potentially removed in favour of plaintext storage on servers outside the user's control.

From the original announcement:

> If you are a current Firefox Sync user, we’ll continue to sync your data between your devices.

So I guess the old option will still be maintained, at least during the testing phase.

Re: Mozilla adopts plain-vanilla password sign-in for Firefox sync

#30
post #18

Earlier quoted context omitted.

Those who would sacrifice privacy for convenience deserve neither.

So you're implying that 99% of humanity will have no privacy nor security?

In the first world, we're already there thanks to google, apple, MS, etc.
Post reply on HN