Live data from Hacker News

New Persona Beta: Millions of Users Ready to Log In using Any Browser

identity.mozilla.com

71–80 of 188 posts

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#71
post #66

Earlier quoted context omitted.

> I don't understand why it doesn't have more mindshare. Because all they've published so far is API specs and fluffy PR sites that try to portray it as "oh so much better" without offering any insight about why it is better. They can claim "more privacy" all day long, but without any details about what gets stored where and why it is supposed to be safer, they don't make a compelling case. Look at this page for exam…

Yow, that's rough. We try really hard to publish docs that will help non-technical users, sites considering using Persona, and potential identity providers. The best starting point is probably the top-level MDN page: https://developer.mozilla.org/docs/Persona

I am a technical user. I just don't want to wade through source code or watch 1 hour long videos to understand why this is supposedly secure. I can accept that not telling ID providers where users are logging in enhances their privacy (whether they care or not is debatable). However, I do not see why accounts are protected better, especially compared to different passwords for every site.

What is my identity tied to? The browser and the given e-mail address? Can anyone who has access to these fake my identity? What countermeasures can I take if that happens? A simple password change is probably out of the question. Such are the questions I'd like to be able to answer, but with the provided, easily accessible information, I cannot.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#72
post #23

Before they push Persona more, can someone walk over to the team that's running http://www.getpersonas.com/en-US/ and either disconnect their servers or lock them to their chairs until they finish the migration? I understand the pain of rebranding assets, I do. But if you're going to rebrand to a product your company is already using, it has to be fast. And Mozilla, the 2 year anniversary is in July...

The migration is actively underway! The site will be shut down in a time scale ordering on weeks.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#73
post #3

I do see the huge potential benefits of the system but have a couple of concerns. I'm concerned that a 'one password' for everything can be more of a liability if your password is stolen/lost and make phishing potentially more lucrative. Also concerned about a centralised password store - people make mistakes and if there was some DB leak/hack it could be damaging as it would not be contained within one system (if I'…

Persona should add two-factor authentication. For that matter, any open-ID or similar technology should add that.

Persona leaves authentication entirely up to the identity provider. In the case of the fallback identify provider that you're probably seeing, they choose passwords. Other identify providers can choose any method of authentication that they want to use.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#74
post #23

Before they push Persona more, can someone walk over to the team that's running http://www.getpersonas.com/en-US/ and either disconnect their servers or lock them to their chairs until they finish the migration? I understand the pain of rebranding assets, I do. But if you're going to rebrand to a product your company is already using, it has to be fast. And Mozilla, the 2 year anniversary is in July...

getpersonas.com is currently read-only [0], "Personas" have been renamed to "Themes" on addons.mozilla.org [1], and the getpersonas.com domain should go away within two weeks [2].

[0]: https://blog.mozilla.org/addons/2013/03/27/getpersonas-com-i...

[1]: https://addons.mozilla.org/en-US/firefox/themes/

[2]: https://blog.mozilla.org/addons/2013/02/28/getpersonas-com-m...

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#75
>> type in email, login to yahoo...

Wait. So, my email provider (Yahoo) can now keep track of every website I login to, if he wants? How can I stop Yahoo being the middleman?

Second question, if an attacker knows my Yahoo password, can he potentially login to _all_ Persona-powered websites with my email then?

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#76

Earlier quoted context omitted.

Er... "they" have also published the full source code involved (at https://github.com/mozilla/browserid ) and a privacy policy at http://www.mozilla.org/en-US/persona/privacy-policy/ that you can compare to said source code as desired, if you're using Mozilla's identity provider. As far as the architecture of the overall thing, there are also http://identity.mozilla.com/post/7899984443/privacy-and-brow... and http://…

Not even the links you posted tell me a) where certificates are stored and how they are protected, b) what measures are taken to prevent unauthorized use of those certificates by the ID provider, the browser (plugins?), other entities, c) how the act of entering an e-mail address is secure (other people may have access to my computer and know my e-mail address). Admittedly, I didn't watch the 1 hour presentation vide…

Those are all great questions, indeed. I'll see if I can get people to answer them!

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#77
post #60

Earlier quoted context omitted.

There's no reason for it to be integrated in the browser?

Browser integration is actually supposed to be one of the core pieces of Persona. The idea is that by building the Persona login process directly into the browser (as opposed to it requiring a popup/webpage) then phishing attacks may be somewhat mitigated.

Also, it's more private. With a native browser implementation, you don't communicate with persona.org every time you log in to a website, you only have to trust your browser to store your cached authentication credential.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#78
I don't like Persona, personally. Email is not an identity. When we connect with email and passwords, both fields are keys (in the open-the-door metaphor). To make the password a secret key, we can't check it for uniqueness so we need a less secret key that will be checked for uniqueness. I think it's important that users can easily modify both keys without loosing their identity.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#79
post #39

I tried to log in to this site https://current.trovebox.com/ which was linked on the Persona home page: http://www.mozilla.org/en-US/persona/ I tried to use my gmail address and it gave me this: http://dl.dropbox.com/u/13941904/persona.png Am I just making up a password for a Persona account and it's using my email address as the user id? I can see how some people would type in their gmail password in by mistake.

> I can see how some people would type in their gmail password in by mistake.

I can see how this could be a big problem once one ID provider decides he'd be interested in grabbing and abusing such credentials. The natural password related to the e-mail address for most people is that of the e-mail provieder.

Re: New Persona Beta: Millions of Users Ready to Log In using Any Browser

#80

Earlier quoted context omitted.

This is off the top of my head so maybe somebody will correct me, but: Persona is a login system that cares about your privacy. With social login systems, the website you are logging into contacts the social login provider (Facebook/Google+/Twitter/what-have-you) when you attempt to log in. So you end up leaving a trail of breadcrumbs behind you of every site you visited (and used a social login on). Further, many pe…

If Persona would care about anyone's privacy, they won't use emails. Logging in with, say, Twitter account is less secure in aspect Twitter knows what sites you log in, but more secure in aspect the sites can't spam you unless you allow them to do so.

The login string looks like an email, but it is only for convenience. Any thing that looks like an email address, and for which the domain will authenticate it using the persona protocol, can be used. Or even an address at mockmyid.com
Post reply on HN