What happens to my account if Persona dies or is temporarily down? Does that mean that I'm locked out?
Why we love Mozilla Persona
31–40 of 164 posts
Re: Why we love Mozilla Persona
#32Give me separate logins and KeePass any day.
Re: Why we love Mozilla Persona
#33Persona is an elegant, powerful idea that is 100% in the users interest. I dearly want to see it gain traction. Kudos for disseminating your enthusiasm.
https://github.com/mozilla/mod_authnz_persona
(I know Apache may not be that popular with the HN crowd anymore, but I don't currently have the time to dive into nginx and do the same for it. Nevertheless, if anyone wants to do that, I'd be happy to answer questions and provide pointers into the Apache code.)
Re: Why we love Mozilla Persona
#34Earlier quoted context omitted.
2FA is a nice add one but not a panacea. Any account will be compromised - it's only a matter of time. When that happens, it's best (as recent articles in Wired, Ars Technica and others demonstrate) to have a broad account "ecosystem".
Hm, interesting. I see your point. What about Facebook/Google/Twitter Sign In buttons - do you think Persona is an improvement over those?
Edit/update: if compromised, you loose all linked accounts, however, with google/fb/.... it is the same, but this is less leaky to 3rd party, if this comes as default login, then we would have only a dozen of logins (persona/email, + important accounts, e.g. banking something similar... ), not ~100 of them, thus resetting 100 passwords is just 1 action
Re: Why we love Mozilla Persona
#35Earlier quoted context omitted.
My understanding of the technology is that the endgame for persona is that you don't have to trust a third party. Instead, the authentication will be provided by the browser itself (the protocol behind Persona is called Browser ID). The current implementation is just a shim until browsers provide support for it natively.
The authentication will actually be provided by your identity provider (which will usually, but not necessarily, be your email provider).
Re: Why we love Mozilla Persona
#36Yet another OpenID/OAuth/Whatever? Another SPOF. Give me separate logins and KeePass any day.
And, quite importantly, running your own identity provider (which is another SPOF in many systems) is pretty straightforward and well-defined in the Persona ecosystem.
Re: Why we love Mozilla Persona
#37But it also proof that being awesome not only is not good enough to be successful, but simply doesn't matter. The user is not interested in a solution that is awesome, but one that doesn't scare him. And a big ugly third-party popup is as scary as stuff on the web gets these days.
Remember Ogg Vorbis?
Re: Why we love Mozilla Persona
#38Earlier quoted context omitted.
The authentication will actually be provided by your identity provider (which will usually, but not necessarily, be your email provider).
Did they give up on the in-browser stuff? Or did I just get the plan completely wrong then?
Re: Why we love Mozilla Persona
#39In principle, Persona is great. Not storing passwords is awesome, a non-FB/Google/Twitter identity option is important. I would encourage you, though, to look carefully at your login completion metrics. I implemented Persona on my site ( http://www.sixquestions.co ) to have a pure email option and although users clearly prefer it, about 35% complete the Persona login flow successfully. That's 10 points lower than our…
Re: Why we love Mozilla Persona
#40> We think that Persona is a great attempt at improving usability, security and privacy... We use Persona and love it. However, I wouldn't trust Persona for securing sensitive information. There seems to be no password requirements (at least when I checked months ago.)
I built my own IdP that has 2-factor auth, for example: https://www.persowna.net/