Live data from Hacker News

New Persona Beta: Millions of Users Ready to Log In using Any Browser

identity.mozilla.com

151–160 of 188 posts

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#151

Earlier quoted context omitted.

I'm personally not a big fan of social sign in, and i doubt i'm going to use persona (at this time). Persona seems like to me kinda like what the chinese are doing with requiring people to use .gov ids on the web. Sure in china it will be by force and here it will be opt in, but in my eyes the result will be the same: making it easier to track people across the web. I don't feel like persona solves the ability for a…

You can run your own persona identity provider on your own domain, then use an email address at that domain to log in. You get to control the authentication, the password policy, decide on multi-factor, etc. This actually very much can solve the inability people have to control their identity on the web.

When i think of people controlling their identity, i dont think of just an email address. I think of their name, their gender, what they look like and the context their data is put in on the web.

Persona seems like it has everything to do with the signup/login process, and not the actual identity of the person who already has some kind of data of that kind floating around the internet (the kind people want to sell to others).

There's no way that this gives someone the ability to go back and erase whats already out there now and somehow give them control over where their information resides and how it's used more than it is now.

Maybe i'm missing something, but this doesn't seem to provide any more utility that i need now since i haven't even incorporated any social login to my site anyways (and don't plan on it either).

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#152
post #133

Earlier quoted context omitted.

Actually, it's my biggest problem with Persona is that the source of my identity is not me, but some third party I have to trust. I run my email addresses on my own (physically-owned) servers. I know various approaches to filtering spam, and the best one in my experience is to not have a littered inbox is to have a private non-dictionary per-service email address and not expose it anywhere else. The only mandatory th…

Actually, there's no reason you can't write your own personal identity provider: https://developer.mozilla.org/en-US/docs/Persona/Implementin...

I know that. It's just depending on domain name "ownership" (and even though it's called so, it's temporary lease, not purchase of property), in exactly the same way general audience depends on email account "ownership".

Except for the fact, if one's email account or the whole provider goes down, they should still be able to login with old-fashioned password credentials. With Persona, unless the site has a backup authentication method, they're out of luck.

This effectively means I've to stick with my domain name forever.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#153
post #137

Earlier quoted context omitted.

This is correct, but the whole thing is marketed as email address, so it will be used as an email address, i.e. means of contacting me. Now, consider I want to try some service I don't trust. I sign in with a email-looking identifier (which doesn't work as email address) and use the site for some time. Eventually, I become fond of this service and want it to start contacting me. With 123done.org I can't do this, nor…

Hopefully, the existence / use of non-emailable browserid providers would encourage sites to accept alternate / custom 'primary' email addresses. It's definitely a chicken-and-egg problem though, and far from guaranteed that it would be resolved happily. And I'm in complete agreement on the marketing, and it's a problem for this setup - the system is young though, maybe this can be changed. Though honestly I suspect…

Found out that Persona team do encourage this: https://developer.mozilla.org/en-US/docs/Persona/The_impleme...

Personally, I wouldn't call email addresses identities, and just say they're credentials. But Mozilla clearly has another idea on what the identity is.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#154

Earlier quoted context omitted.

After you click a button labeled sign in, the popup reads "[Your site] uses Persona instead of usernames to sign you in. To sign in with Persona, please enter your email address." I'm not sure I can do better than that text -- do you have any suggestions?

Sure. How about adding "This does not require registration in advance." (Or "previous registration" or "a previous account" or whatever is clearest). The problem is users searching for "Create Account" instead of "Sign In" when there is no "Create Account". Edit: Sorry, on review this post was tangential to the point to which you were responding (about why the email is needed). It was targeted more at the point about…

Plus the usual "We will never sell your email info" etc. etc.

Also, the "Learn More" blue text disappears on a gray background. That part needs to pop.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#155
Oh neat, it seems my current Firefox (20) works with Persona now when third party cookies are disabled. This was a huge problem before when I was playing around with it a few months ago (it would flat-out never properly authenticate when I was testing it before). Didn't think the new cookie policy would roll out of testing so quickly.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#156

Earlier quoted context omitted.

I'm personally not a big fan of social sign in, and i doubt i'm going to use persona (at this time). Persona seems like to me kinda like what the chinese are doing with requiring people to use .gov ids on the web. Sure in china it will be by force and here it will be opt in, but in my eyes the result will be the same: making it easier to track people across the web. I don't feel like persona solves the ability for a…

You can run your own persona identity provider on your own domain, then use an email address at that domain to log in. You get to control the authentication, the password policy, decide on multi-factor, etc. This actually very much can solve the inability people have to control their identity on the web.

It appears to me that in order to run your own Persona Identity Provider you must setup and maintain an SSL capable webserver for your email domain, equipped with a certificate that chains up to one in Mozilla's bundle (no self-signed cert), configured to handle the Persona protocol and authenticate you. FWIW, some (including myself) run email-only domains/servers with unnecessary services (httpd!) purposely disabled in order to reduce attack surface and administration chores.

AFAICT, even if you do setup your own Persona Identity Provider you would not have control over Relying Parties (websites you login to) and how they verify identity assertions. IOW, you couldn't prevent Relying Parties from taking the easy way out and issuing backend calls to Mozilla's verification service. Which would leak Email Address, Login Site, and time information to Mozilla. Nothing against Mozilla BTW, it's just a third party in such contexts and thus should not be privy to any information about account creations and/or logins.

I think those who run a strong browser config (limiting third party scripts, third party cookies, and/or cross site requests) would have to weaken their setup to even allow the Persona mechanisms to work correctly.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#157
Just one privacy question: Imagine If I log in using the same email to Service1 and post some comment. And later, using the same identity I log in to Service2 to post some pictures. Does Service1 and Service2 (imagine the share some data) know that it was the same person?

PS. Good work, it looks quite convincing!

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#158
post #96

>> type in email, login to yahoo... Wait. So, my email provider (Yahoo) can now keep track of every website I login to, if he wants? How can I stop Yahoo being the middleman? Second question, if an attacker knows my Yahoo password, can he potentially login to _all_ Persona-powered websites with my email then?

No, because Persona mediates, and Yahoo only knows that you're using your Yahoo identity with Persona, nothing more. That's a key privacy property of Persona. However, if you use the "login with Yahoo" button (or Google or Facebook), then yes, they can track all of your activity. To your second point: great question! No, the attacker cannot. We still protect your other email addresses with a Persona password.

> Yahoo only knows that you're using your Yahoo identity with Persona

But Yahoo still knows that I'm on that website.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#159
post #157

Just one privacy question: Imagine If I log in using the same email to Service1 and post some comment. And later, using the same identity I log in to Service2 to post some pictures. Does Service1 and Service2 (imagine the share some data) know that it was the same person? PS. Good work, it looks quite convincing!

They both know it was the validated owner of user@example.org, so if Service1 and Service2 compare their users, they will see the same e-mail address.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#160
post #96

Earlier quoted context omitted.

No, because Persona mediates, and Yahoo only knows that you're using your Yahoo identity with Persona, nothing more. That's a key privacy property of Persona. However, if you use the "login with Yahoo" button (or Google or Facebook), then yes, they can track all of your activity. To your second point: great question! No, the attacker cannot. We still protect your other email addresses with a Persona password.

> Yahoo only knows that you're using your Yahoo identity with Persona But Yahoo still knows that I'm on that website.

How?
Post reply on HN