Live data from Hacker News

Announcing the First Beta Release of Persona

identity.mozilla.com

191–200 of 207 posts

Re: Announcing the First Beta Release of Persona

#193

Earlier quoted context omitted.

>No more password column in your database... Who has liability when a user of mine says their account got hacked? The email provider? My site? Mozilla? If one of my users has $100 go missing from their account, then they are going to expect me to replace it, not the email provider, not mozilla. I don't like the idea of shifting security to a outside platform, because I still retain all the liability when things go ba…

How can any website protect a user against key loggers, spyware or any other form of a compromised client machine? If the client machine is compromised, any login method is broken.

As mentioned above, two factor authentication.

Re: Announcing the First Beta Release of Persona

#194
post #138

Earlier quoted context omitted.

Then you would not use your primary "super secure" email as your browserId, but a secondary mail account.

The most valuable thing about your email account is that it's your password recovery mechanism. What ever email account you use for password recovery or logging into things becomes the "super secure" email account. There is no message in my email that I care more about than the one that might give you access to my bank accounts.

Passwords are not the only authentication option. This could be a good way to replace all your passwords with something stronger (2 way, fingerprints, you name it) if your provider supports them.

Re: Announcing the First Beta Release of Persona

#195

Earlier quoted context omitted.

How can any website protect a user against key loggers, spyware or any other form of a compromised client machine? If the client machine is compromised, any login method is broken.

As mentioned above, two factor authentication.

Not really. All 2 factor authentication schemes that I've seen give no protection against a compromised client machine.

In theory you could probably device a scheme that would require the use of two independent devices to perform any sensitive action and that would guarantee that if only one of the devices is compromised, the attacker would have no way to perform any action in a name of the user. But I'm afraid any such scheme would be a complete failure from a usability perspective.

Re: Announcing the First Beta Release of Persona

#196

Earlier quoted context omitted.

The original name, "Browser ID", made it clearer. Basically, your browser knows your identity, so it can automatically authenticate you with any supporting website. You never have to set up an account with the website and you never have to enter a password. That's my understanding of it anyway.

in 5 years many people using the web will have no idea what you're talking about when you say "browser" :)

I think the majority of people have no idea what a browser is and never have.

Re: Announcing the First Beta Release of Persona

#197

Earlier quoted context omitted.

As mentioned above, two factor authentication.

Not really. All 2 factor authentication schemes that I've seen give no protection against a compromised client machine. In theory you could probably device a scheme that would require the use of two independent devices to perform any sensitive action and that would guarantee that if only one of the devices is compromised, the attacker would have no way to perform any action in a name of the user. But I'm afraid any s…

When the second factor is a "rich" device, such as a smart phone, attaching transaction information to the interaction would be a trivial - instead of texting "The code is 1234", text "Transfer $100 to account 9876" or "Login attempt from IP 1.2.3.4, FooCom Inc, Springfield, Oregon, USA.", followed by "If correct, enter code 1234. If not, DO NOT enter the code and contact us at .. "

Re: Announcing the First Beta Release of Persona

#198

This seems to be a nice solution if you are on your own home/work computer and have your email open. They didn't really explain much on HOW it works but the problem I'm seeing is that if I am at a public computer and want to login I have to log in to my email account first and click on the persona link. I guess the benefit here is that I only need to remember 1 password (my email address password) but my email passwo…

You can have a provider that requires no auth. Try entering whatever@mockmyid.com as an address.

Re: Announcing the First Beta Release of Persona

#199

This seems to be a nice solution if you are on your own home/work computer and have your email open. They didn't really explain much on HOW it works but the problem I'm seeing is that if I am at a public computer and want to login I have to log in to my email account first and click on the persona link. I guess the benefit here is that I only need to remember 1 password (my email address password) but my email passwo…

That's not really how it works. You verify your email address once, and after that you can just log in with your address and password. You don't have to click on an email link every single time you log in.

[deleted]
Post reply on HN