Live data from Hacker News

Mozilla Persona and Surveillance

identity.mozilla.com

21–30 of 59 posts

Re: Mozilla Persona and Surveillance

#21
post #20

The best things in Persona's favour: 1) A lot of people are working on it (hopefully eyeballs translate to fewer flaws) 2) You can host your own 3) Eventually when browsers are in on the game, it can be decentralised The best response Mozilla could give is to highlight the above and ask for more help from those able to give it to make those things come true sooner. We all know where we are today, so let's just get to…

> it can be decentralised

Technically, yes. Realistically, highly unlikely.

What's going to happen, at best, is that email service providers like Google and Microsoft will begin to support Persona. Either as a replacement for OpenID, or in addition to it. A negligible minority of the human population, such as regular HN readers like you and I, might opt to implement Persona on our own servers, but everyone else will remain hostages of their respective email service providers.

Re: Mozilla Persona and Surveillance

#22
The most important line for me from the blog post was

    Third, we’d rather not engage in an arms-race with US 
    government agencies. We’d rather focus on efforts to 
    change the Law to respect user data wherever it lives.
This effectively tells a lot about Mozilla's intent.

Re: Mozilla Persona and Surveillance

#23

The statement that Mozilla should have issued: "Some have claimed that we should move Mozilla out of the US. Unfortunately, for reasons of connectivity, workforce, ties to US market, legal issues and restructuring costs we are not able to do that. Current (recurring) developments in the US have shown that our government can not be trusted. No amount of legislation is going to achieve a fully accountable government. B…

The last bit here is a reach. For starters, Persona uses SSL, so it's encrypted. But more broadly, if you're going to use centralized, third-party authentication mechanism you could do far, far worse than Persona. I'd go so far as to say if your site is implementing its own authentication system, you could do yourself even more damage with a poor implementation.

Your critique seems to missed an important part about Persona's design: "It’s also worth pointing out that we do take certain technical measures to limit the data we collect. We’ve designed Persona so that the identity provider – including the fallback Identity Provider that we run – does not learn your browsing history. We consider that a good security practice, not specifically because of surveillance, but generally because collecting data without a user benefit just creates risk."

Further, the main "centralized" risk would be their default identity provider. If you don't want to use that for your domain, you can provide your own, and host it in another country. In this case, Mozilla's servers aren’t even being contacted when you authenticate.

Re: Mozilla Persona and Surveillance

#24

The statement that Mozilla should have issued: "Some have claimed that we should move Mozilla out of the US. Unfortunately, for reasons of connectivity, workforce, ties to US market, legal issues and restructuring costs we are not able to do that. Current (recurring) developments in the US have shown that our government can not be trusted. No amount of legislation is going to achieve a fully accountable government. B…

Plus:

"Some have called on us to move Persona servers outside the US..."

But: "We’d rather focus on efforts to change the Law to respect user data wherever it lives."

What?! Who says it's an either-or question? IT'S NOT! IT HAS NEVER BEEN!

ANY and ALL means must be used, given the gravity of the situation!

Re: Mozilla Persona and Surveillance

#25
post #21
post #20

The best things in Persona's favour: 1) A lot of people are working on it (hopefully eyeballs translate to fewer flaws) 2) You can host your own 3) Eventually when browsers are in on the game, it can be decentralised The best response Mozilla could give is to highlight the above and ask for more help from those able to give it to make those things come true sooner. We all know where we are today, so let's just get to…

> it can be decentralised Technically, yes. Realistically, highly unlikely. What's going to happen, at best, is that email service providers like Google and Microsoft will begin to support Persona. Either as a replacement for OpenID, or in addition to it. A negligible minority of the human population, such as regular HN readers like you and I, might opt to implement Persona on our own servers, but everyone else will…

Decentralisation can happen gradually.

By using a browserId enabled user agent/browser and an email provider who has implemented the browserId -protocol you already have a fully decentralised Persona experience.

Re: Mozilla Persona and Surveillance

#26
One great thing about Persona is that it doesn't have to get involved every time I log into some website. The keys can be cached, so Persona doesn't need to know which websites I visit the most frequently, how long I spend on each site, which pages I read, etc. Persona just provides the identity and stops there. In that sense, Persona's very design makes it an unattractive target of surveillance. Not much data there.

Right now, Mozilla knows my email address, my (hopefully salted and hashed) password, some keys associated with said password, and the set of IP addresses from which I ever accessed Persona. Maybe also the set of IP addresses from which its key was requested, but that's not a particularly useful piece of information when NSA is trying to figure out what I'm up to.

However, Two of the planned changes to Persona gets me worried a little. The first is that Persona will allow people to add multiple email addresses to each account and choose which one to use at any given time. This means that if NSA gains access to the contents of a Persona server, they'll be able to link several (seemingly unrealted) email addresses to the same account. If you're a heavy Redditor, imagine that somebody will be able to find out every throwaway account that you made and abandoned over the years to talk about things you don't want traced back to you. That's the sound of the Eureka! that the NSA agent utters when he finds out that the person who has been posting anti-factory-farming comments all over the place is actually the same guy who retweeted some anti-Esso catchphrase, who is the same guy whose personal blog contains pictures from a recent trip to Pakistan.

My second worry is that Mozilla expects email service providers to serve as a Persona provider for their users. If I'm not sure whether I want to trust the Mozilla Foundation (the good guys) with information about my various alter egos, I'm definitely going to be wary of giving Google, Yahoo, and Microsoft the same kind of information. Although it's possible for you to be your own Persona provider, realistically, not many people are their own OpenID providers at the moment, and not many of them are going to be their own Persona provider, either. Decentralization is often advertised as one of the better features of Persona, but I suspect that it's going to remain little more than an advertisement. Everyone else will just use Google-hosted Persona with their Google-hosted email, with no real improvement of privacy.

Re: Mozilla Persona and Surveillance

#27
post #21
post #20

The best things in Persona's favour: 1) A lot of people are working on it (hopefully eyeballs translate to fewer flaws) 2) You can host your own 3) Eventually when browsers are in on the game, it can be decentralised The best response Mozilla could give is to highlight the above and ask for more help from those able to give it to make those things come true sooner. We all know where we are today, so let's just get to…

> it can be decentralised Technically, yes. Realistically, highly unlikely. What's going to happen, at best, is that email service providers like Google and Microsoft will begin to support Persona. Either as a replacement for OpenID, or in addition to it. A negligible minority of the human population, such as regular HN readers like you and I, might opt to implement Persona on our own servers, but everyone else will…

Realistically and perhaps sooner than you think They are finishing up the LDAP based provider, once that happens, you could hook it up to most company-wide authentication systems.

Once that's working @university.edu and @bigco.com would authenticate directly with the organization. That'll be huge. This is a very very high value feature, I expect it to be the driving force for adoption.

One of the big challenges of large organizations is shutting someone off once they've left the company. This provides very unintrusive way to do so for applications that use Persona. I could see large organizations requiring that all logins use Persona (and the @organization domain).

Re: Mozilla Persona and Surveillance

#28
post #25
post #21

Earlier quoted context omitted.

> it can be decentralised Technically, yes. Realistically, highly unlikely. What's going to happen, at best, is that email service providers like Google and Microsoft will begin to support Persona. Either as a replacement for OpenID, or in addition to it. A negligible minority of the human population, such as regular HN readers like you and I, might opt to implement Persona on our own servers, but everyone else will…

Decentralisation can happen gradually. By using a browserId enabled user agent/browser and an email provider who has implemented the browserId -protocol you already have a fully decentralised Persona experience.

My problem is with the "email provider" part. In the real world, it just means Google, Yahoo, Microsoft, and handful of firms (like Rackspace) that provide hosted email solutions for a fee. You might call it "decentralized", but I'd call it "mostly centralized".

Re: Mozilla Persona and Surveillance

#29
post #7
post #3

"First, it’s not clear to us that other governments have any less intrusive surveillance activities." Well, it is clear the US has it. That should be enough. There are some unknowns unknowns, but this is a known unknown. There are other governments with the same willingness and capabilities of spying on everyone (do not move to China), but most of the countries in the world do not have a Government with both willingn…

NSA and GCHQ are very good at math and very good at surveillance . Not engaging in an arms race with well funded, very smart, government agencies is probably a good idea. If they think you're a criminal (doesn't apply to Mozilla) they will coerce foreign governments to cooperate - see for example the illegal attacks on Mega or the domain seizures for gambling or torrent sites. But we know, from ECHELON, that they're…

NSA and GCHQ are but 2 on a long list of government intelligence agencies with exceptionally skilled individuals. It is madness to believe that even if you moved to a fully neutral location [if you can find one] you wouldn't be compromised for the information you store, through agents/moles/whatever or otherwise.

Re: Mozilla Persona and Surveillance

#30

The statement that Mozilla should have issued: "Some have claimed that we should move Mozilla out of the US. Unfortunately, for reasons of connectivity, workforce, ties to US market, legal issues and restructuring costs we are not able to do that. Current (recurring) developments in the US have shown that our government can not be trusted. No amount of legislation is going to achieve a fully accountable government. B…

The last bit here is a reach. For starters, Persona uses SSL, so it's encrypted. But more broadly, if you're going to use centralized, third-party authentication mechanism you could do far, far worse than Persona. I'd go so far as to say if your site is implementing its own authentication system, you could do yourself even more damage with a poor implementation. Your critique seems to missed an important part about P…

I know nothing about Persona. I have never used, and I have not read anything about it. But that much is clear to me: the communication between you and the Persona provider can happen very much over an encrypted channel, but the data in the Provider is not encrypted with a key which you only know. The Persona provider has the data in the open (except passwords, which are hashed)

This whole fiasco has shown a weakness in the system which was there all the time, but little acknowledged: it is not about encrypting communications anymore. The eavesdropping risk is well understood and there are technologies available to get rid of it (SSL, SSH tunnels, whatever). But now we need to encrypt the data everywhere. Nobody can be trusted with the data anymore because the government can be accessing that data, and they do not need to eavesdrop: they just need to send a letter and implicitly threaten with litigation and imprisonment to obtain whatever data they want.

This makes the technological solutions much more challenging, and some services can probably not be provided. How does Facebook provide services to their users if the data they have must be encrypted and they can not access it? How to share with friends photos if they are encrypted? Maybe creating ad-hoc group passwords to share data? I do not know, it is difficult.

Post reply on HN