Live data from Hacker News

Hoomi Delivers on Facebook Login’s Broken Promise

blog.hoomi.co

11–20 of 30 posts

Re: Hoomi Delivers on Facebook Login’s Broken Promise

#11
post #8
post #2

OP here. Excited to start showing this stuff to the world. We think identity and login are really broken today, especially on devices that are becoming smarter (mobile, TV, etc.), and we are hoping to provide a solution that lets you take an identity with you wherever you want/need it. Since we're not a social network, we can avoid a lot of the risk and confusion about how to use the product without accidentally shar…

Thanks for this great product. Definitely going to try this out. What are your plans to push this into market and How are you planning to attract both app devs and end users to use your product?

Thanks for the interest!

We're encouraging developers to use this alongside social login (or as a replacement for building their own email/password-based login). Developers can avoid having to build and design large amounts of UX around login, registration, email/phone verification, password resets, etc. by adopting Hoomi, while still giving their users an alternative to social login.

We plan to add a number of compelling features for both users and developers. These will increase the value of a Hoomi account as well as the benefit of adding Hoomi login to your applications.

Re: Hoomi Delivers on Facebook Login’s Broken Promise

#13

I'd say Mozilla's Persona delivers it best: * Mozilla doesn't have any information on you * Mozilla doesn't store your password if possible, and instead falls back to your email provider (but they do NOT learn which site you logged into) * It can eventually be decentralised and browser-integrated (though this may have been abandoned) * The site only knows your email address I can't remember, but I don't know if Mozil…

Mozilla also has a reputation for being concerned about privacy.

Re: Hoomi Delivers on Facebook Login’s Broken Promise

#14
post #12

Why not take this all the way? Why require e-mail and/or cell phone? You could also distinguish yourself vis-a-vis persona which requires an e-mail address.

You're exactly right. We don't require email addresses or phone numbers to be requested from users by apps. Those are just ways to get and verify a Hoomi account. Once a user authorizes an app, the app only gets a stable, unique identifier (unrelated to the email address or phone number on the account).

Re: Hoomi Delivers on Facebook Login’s Broken Promise

#16
Why would successful developers and publishers integrate Hoomi?

Is user demand for Hoomi their only incentive? Or is there a positive benefit for them as well?

If the former, it's not clear why developers would rush to support it until it accumulates a very large and uncompromising user base; and building that user base will be hard without a lot of apps/sites already integrating it.

Re: Hoomi Delivers on Facebook Login’s Broken Promise

#17

Why would successful developers and publishers integrate Hoomi? Is user demand for Hoomi their only incentive? Or is there a positive benefit for them as well? If the former, it's not clear why developers would rush to support it until it accumulates a very large and uncompromising user base; and building that user base will be hard without a lot of apps/sites already integrating it.

There's definitely a benefit to developers. Hoomi provides an alternative to social login as well as an easy way to get single sign-on across their suites of applications. Furthermore, developers can adopt Hoomi rather than adding their own email/password-based login mechanism and avoid having to build screens for login, signup, email/phone verification, password reset, account management, etc. Essentially, developers can treat Hoomi as their login-as-a-service provider.

Re: Hoomi Delivers on Facebook Login’s Broken Promise

#18

I'd say Mozilla's Persona delivers it best: * Mozilla doesn't have any information on you * Mozilla doesn't store your password if possible, and instead falls back to your email provider (but they do NOT learn which site you logged into) * It can eventually be decentralised and browser-integrated (though this may have been abandoned) * The site only knows your email address I can't remember, but I don't know if Mozil…

It's pretty darn easy to integrate, too; I used it for a toy project, and it was really quite pleasant!

Re: Hoomi Delivers on Facebook Login’s Broken Promise

#19

I'd say Mozilla's Persona delivers it best: * Mozilla doesn't have any information on you * Mozilla doesn't store your password if possible, and instead falls back to your email provider (but they do NOT learn which site you logged into) * It can eventually be decentralised and browser-integrated (though this may have been abandoned) * The site only knows your email address I can't remember, but I don't know if Mozil…

> I can't remember, but I don't know if Mozilla knows which sites you log into, either.

I'm fairly certain it does not, and that this was built into the protocol from the start. Please let me know if I'm mistaken.

Persona is a fantastic protocol. Too bad Mozilla seemed too eager to drop support...

Re: Hoomi Delivers on Facebook Login’s Broken Promise

#20
post #6

Earlier quoted context omitted.

So, the biggest draw of the social-network-based logins (as well as their biggest flaw) was that you probably already had an account. With Hoomi, what's the advantage of using your Hoomi account rather than just giving an email address? Also, how does this compare (in both features and privacy) to Persona?

Hoomi sits somewhere between email/password login and social login. Users still get the benefit of Single Sign-on (that grows as more developers adopt), but don't have to have (or tie their account to) a social profile. You're also welcome to use your phone number to create a Hoomi account. As far as Persona goes, one of the major differences is the primacy of mobile as a medium for login. And while Persona focuses o…

Unlike Persona, Hoomi will be able to know which application the user logs into, and for how long, correct? From what I've seen so far, it seems like the user and/or the application will have to make requests to Hoomi's servers.

Does this mean that Hoomi will become essentially a single point of failure: if Hoomi's servers get compromised, the malicious agent will be able to collect the user's identities and activities? Especially if a lot of apps implement Hoomi, then it may even be possible for the malicious agent to profile the user's entire digital life by tracking them everywhere.

This is what Persona aimed to prevent: it delegates the responsibility of identifying users to a third party and multiple such third parties can exists. Also, as far as I remember from when I used it, it also is designed to ensure that the authenticator have no knowledge of what the user is up to.

Post reply on HN