Live data from Hacker News

Mozilla Persona and Surveillance

identity.mozilla.com

11–20 of 59 posts

Re: Mozilla Persona and Surveillance

#11
post #3

"First, it’s not clear to us that other governments have any less intrusive surveillance activities." Well, it is clear the US has it. That should be enough. There are some unknowns unknowns, but this is a known unknown. There are other governments with the same willingness and capabilities of spying on everyone (do not move to China), but most of the countries in the world do not have a Government with both willingn…

> Move the company out of the US. > Read: we are afraid to lead here... Both the non-profit and for-profit arms of Mozilla are funded almost entirely by Google. It's a pretty safe bet that they'll follow Google's overall lead in dealing with the government. https://en.wikipedia.org/wiki/Mozilla_Foundation - "funded almost exclusively by Google Inc." https://en.wikipedia.org/wiki/Mozilla_Corporation - "Google pays Moz…

That doesn't really make sense in this case. Mozilla does get a lot of cash from Google, but Mozilla has a strong enough mission (see the manifesto) to make sure it's not a Google sockpuppet.

Re: Mozilla Persona and Surveillance

#12
post #2

Any plans to pin the login.persona.org SSL certificate in browsers? It seems like a pretty tasty MITM attack target, especially while most identity providers don't have native persona support. login.persona.org is listed in the key pinning list in Chrome[1], but marked as kNoPins, DOMAIN_NOT_PINNED - whatever that means. [1] http://src.chromium.org/viewvc/chrome/trunk/src/net/http/tra...

Yes and we're tracking it here: https://github.com/mozilla/browserid/issues/2158

That list you see in Chromium (which is now also shared with Firefox) is the list of sites that come with HSTS (https://developer.mozilla.org/en-US/docs/Security/HTTP_Stric...) turned ON.

Re: Mozilla Persona and Surveillance

#13
The statement that Mozilla should have issued:

"Some have claimed that we should move Mozilla out of the US. Unfortunately, for reasons of connectivity, workforce, ties to US market, legal issues and restructuring costs we are not able to do that.

Current (recurring) developments in the US have shown that our government can not be trusted. No amount of legislation is going to achieve a fully accountable government.

Because of this, we are unable to guarantee that Persona is or will be exempt of data requests from one of the government agencies. Even worse: we will not be able to tell you when / what data has been requested. We are and will not be able to confirm or deny data requests. It can be that future legislation forbids us to even make the statements that we are making in this paragraph, so this is maybe the last time that we can tell you this.

The only solution to a private internet is to fully embrace cryptography for all our communications. Until then, you can use Persona at your own risk."

Re: Mozilla Persona and Surveillance

#14
post #5
post #3

"First, it’s not clear to us that other governments have any less intrusive surveillance activities." Well, it is clear the US has it. That should be enough. There are some unknowns unknowns, but this is a known unknown. There are other governments with the same willingness and capabilities of spying on everyone (do not move to China), but most of the countries in the world do not have a Government with both willingn…

> Move the company out of the US. But that's not enough. If they really want to be free from the US's reach they'd have to: - not do business with any companies under US jurisdiction (oops - Google and Microsoft) - not employ and US citizens or permanent residents - warn employees that they could get arrested if they visit the US - ... And given that Firefox is a very visible browser with significant market share, th…

What a load of FUD.

If they want to be able to store a bit of customer information that they don't have to pass over to the US government then they just have to move the company and their servers out of the US.

Why would a company that has nothing to do with the US have to warn employees that they could get arrested if they visit the US?

Re: Mozilla Persona and Surveillance

#15

Earlier quoted context omitted.

> Move the company out of the US. > Read: we are afraid to lead here... Both the non-profit and for-profit arms of Mozilla are funded almost entirely by Google. It's a pretty safe bet that they'll follow Google's overall lead in dealing with the government. https://en.wikipedia.org/wiki/Mozilla_Foundation - "funded almost exclusively by Google Inc." https://en.wikipedia.org/wiki/Mozilla_Corporation - "Google pays Moz…

That doesn't really make sense in this case. Mozilla does get a lot of cash from Google, but Mozilla has a strong enough mission (see the manifesto) to make sure it's not a Google sockpuppet.

Google's funding isn't the end of the story. There are others (e.g. Microsoft) who would be happy to fund Mozilla. The real question is: How much cash could Mozilla get from non-US sources? I'd guess orders of magnitude less, sadly.

Re: Mozilla Persona and Surveillance

#16
post #12
post #2

Any plans to pin the login.persona.org SSL certificate in browsers? It seems like a pretty tasty MITM attack target, especially while most identity providers don't have native persona support. login.persona.org is listed in the key pinning list in Chrome[1], but marked as kNoPins, DOMAIN_NOT_PINNED - whatever that means. [1] http://src.chromium.org/viewvc/chrome/trunk/src/net/http/tra...

Yes and we're tracking it here: https://github.com/mozilla/browserid/issues/2158 That list you see in Chromium (which is now also shared with Firefox) is the list of sites that come with HSTS ( https://developer.mozilla.org/en-US/docs/Security/HTTP_Stric... ) turned ON.

[deleted]

Re: Mozilla Persona and Surveillance

#17
post #5

Earlier quoted context omitted.

> Move the company out of the US. But that's not enough. If they really want to be free from the US's reach they'd have to: - not do business with any companies under US jurisdiction (oops - Google and Microsoft) - not employ and US citizens or permanent residents - warn employees that they could get arrested if they visit the US - ... And given that Firefox is a very visible browser with significant market share, th…

What a load of FUD. If they want to be able to store a bit of customer information that they don't have to pass over to the US government then they just have to move the company and their servers out of the US. Why would a company that has nothing to do with the US have to warn employees that they could get arrested if they visit the US?

Why would a company whose only connection to the US is a few US citizen and/or permanent resident employees have to worry about whether or not certain transactions involve those employees?

You might not know why, but they do. The US is unusually (perhaps uniquely) aggressive in how far it tries to push the reach of its law. It's worth thinking through the implications of that.

Re: Mozilla Persona and Surveillance

#18
post #6
post #5

Earlier quoted context omitted.

> Move the company out of the US. But that's not enough. If they really want to be free from the US's reach they'd have to: - not do business with any companies under US jurisdiction (oops - Google and Microsoft) - not employ and US citizens or permanent residents - warn employees that they could get arrested if they visit the US - ... And given that Firefox is a very visible browser with significant market share, th…

You are probably right, but Mozilla should go down putting up a fight. And this is a fight worth losing.

So Mozilla should throw away their funding, lay off the majority of their employees and then fight the good fight?

How much of Mozilla would be left to do that again?

Re: Mozilla Persona and Surveillance

#19
post #18
post #6

Earlier quoted context omitted.

You are probably right, but Mozilla should go down putting up a fight. And this is a fight worth losing.

So Mozilla should throw away their funding, lay off the majority of their employees and then fight the good fight? How much of Mozilla would be left to do that again?

Mozilla would probably die, and that would be a very bad thing. So you are right, this is not the wisest path (it is the bravest, but the graveyard is full of brave people).

The other option is to contribute to educate the public by being honest. Giving the false hopes that they provide in their statement, they are doing a disservice to the public by downplaying the risk posed by the government.

I would have hoped from more honesty from Mozilla; they should just call it what it is: the US is a police state, so you'd better protect yourself.

Re: Mozilla Persona and Surveillance

#20
The best things in Persona's favour:

1) A lot of people are working on it (hopefully eyeballs translate to fewer flaws)

2) You can host your own

3) Eventually when browsers are in on the game, it can be decentralised

The best response Mozilla could give is to highlight the above and ask for more help from those able to give it to make those things come true sooner.

We all know where we are today, so let's just get to where we want to be tomorrow.

And finally add a link to Github: https://github.com/mozilla/browserid

Post reply on HN