Live data from Hacker News

Open Letter to Mozilla: Bring Back Persona

stavros.io

201–210 of 243 posts

Re: Open Letter to Mozilla: Bring Back Persona

#201
post #101

Earlier quoted context omitted.

"the annoyance that is "Sign up with a username, email address, and password"." I know of an easy way to remove 33% of that ... Email addresses are globally unique, and everyone already knows theirs ... email + password seems like a simple, well accepted and workable solution. Right ?

Emails may be globally unique but they aren't static over time. I have some accounts on websites where the login is an email address I no longer have access to.

Heck, my microsoft account is tied to an email I can no longer access, but I'm not able to change it, because my generic gmail identity somehow got an xbox account tied to it and that apparently means I can no longer transfer my xbox profile from my old email account to my new one.

My appleId has an @mac.com email address which means it is for some reason immutable - I can not change my address. Jobs only knows where emails from apple to me end up, I really don't do much with my appleid anymore other than re-authorize the appstore every month when I need to update xcode.

Re: Open Letter to Mozilla: Bring Back Persona

#203
post #135

Earlier quoted context omitted.

And more importantly, signing in with fb is simply handing over our personal details. I use gmail, I have no problem trading my info for goods and services - I know what they're realistically worth and judge accordingly. But for Fred's Arbitrary Website? Go fuck yourself Fred, I'll hand over exactly as much information as I like.

Really, Facebook/Google get the sweeter end of the deal. They'll know that you use Fred's arbitrary website. They will know when you use it, how often you it, and how long you use it each time. They'll add your new usage patterns to the database they've been building about you for the past decade. They'll correlate your behavior with other users of Fred's arbitrary website.

They already get that from Facebook like buttons on every single page

Re: Open Letter to Mozilla: Bring Back Persona

#206

Earlier quoted context omitted.

Well, yeah, but Persona/BrowserID didn't fail, YOU (Mozilla) failed. BrowerID was the right concept, and it was insanely stupid to create a different frontend branding, to not build the browser integration, to not explain anything well, and then to describe the project as a failure when it hadn't even been implemented at all on your side.

> Well, yeah, but Persona/BrowserID didn't fail, YOU (Mozilla) failed. Did you read the post? This is exactly what the OP said: > I was very bullish on Persona early on, but the fact of the matter is, we failed.

Yes, I wasn't posting to argue with the other poster, I was just writing to clarify and emphasize further the BrowserID aspect of things and other contexts.

Re: Open Letter to Mozilla: Bring Back Persona

#208
post #155
post #22

Earlier quoted context omitted.

Completely optional. Like HN for example.

How do they prevent Sybil attacks and DOS?

Perhaps by limiting the rate at which password-free accounts can be created. If this limit is exceeded then the system switches back to creating user accounts in the normal way.

Re: Open Letter to Mozilla: Bring Back Persona

#209
post #5

I hate that the best user experience for logins is "Login with facebook" or "Login with Google". I don't want to impose that privacy failure on my users, but I also don't want to impose the annoyance that is "Sign up with a username, email address, and password". Offering all of the options is also a compromise that complicates the user experience. Now, here's the sad thing, for me: I didn't even know Persona existed…

Side note: usernames should just be emails these days, they're unique and save all the effort of needing another made up name.

Except that users are really bad at choosing strong passwords. A significant percentage will even use the same email/password combination accross multiple sites. For a site which contains sensitive financial or medical data, it is better to issue a 'username' that contains random characters. (This is the technique the UK government uses when users log in to pay tax)

Re: Open Letter to Mozilla: Bring Back Persona

#210
post #161

Earlier quoted context omitted.

This is essentially the same thing as having your password emailed to you and is insecure for all the same reasons. Youre putting the responsibility of security on the email provider, which you can't control.

> This is essentially the same thing as having your password emailed to you and is insecure for all the same reasons. No, it's essentially the same thing as having a password-reset email sent to one, which is already the case for just about any account anyway . > You're putting the responsibility of security on the email provider, which you can't control. Your email provider is already capable of visiting a site, cla…

[deleted]
Post reply on HN