5 ms·
> And, I didn't even know it was an option until it stopped being an option. Not to take away from your overall point, but you can still very much use persona:
by 21echoes 11y ago
> And, I didn't even know it was an option until it stopped being an option.
Not to take away from your overall point, but you can still very much use persona: https://developer.mozilla.org/en-US/Persona https://developer.mozilla.org/en-US/Persona (linked from https://login.persona.org/ https://login.persona.org/ )
- SwellJoe 11y agoCool. I'll give it a shot. There is a Drupal module for it (I run Drupal on my current primary site, for now), though it only has 38 active installs, which is somewhat worrying.
- iheartmemcache 11y agoFrom what I read (very very briefly), the spec is similar to what OpenID was, in that anyone who runs a web server can become an authentication provider. Ideally there'd be a distributed-hash-table type web-of-trust so its semi-centralized (i.e. somewhat like PGP or BGP routing tables where you peer with people you trust). Now that 1st party browser certificates are available so you get that Trusty-Green-Lock(tm) on all browsers, geeks can theoretically run their own identity service based on some sort of combination of these technologies. (Ideally with the long term outcome solving the "Why Johnny can't have Crypto" problem, maybe using a cell phone app as an RSA SecurID type dongle.) This also has the benefit of letting you authenticate against your bud John's Identity Server, rather than Go-fuck-yourself-Fred's (you'd need token negotiation in there somehow though). Someone smarter than me (DJB where are you?) should piece this together, release it as open source for the end-user, and fund it via expensive Exchange module integration.
- djsumdog 11y agoI still run my own open id, but very few people support open id anymore. Slashdot removed support, shirt.woot removed support after the Amazon buyout ... The only thing I use that still supports it is stack overflow.
- fiatjaf 11y agoSo I can have an authentication provider that is not an email provider and people can have accounts in my provider just to use them in Persona logins?
- StavrosK 11y agoYes, see https://persowna.net/ https://persowna.net/. Setup is as easy as copying a file to your web server.
- jvehent 11y agoThere is an Apache module too: https://github.com/mozilla/mod_authnz_persona https://github.com/mozilla/mod_authnz_persona
- deleted 11y ago[deleted]
- deno 11y ago> Defintely something to note for future UX designs... but Persona, the service hosted by mozilla, is being decommissioned in late 2016. https://groups.google.com/forum/#!topic/mozilla.dev.identity/hkegkFg8Fd8 https://groups.google.com/forum/#!topic/mozilla.dev.identity...
- jvehent 11y ago> In the event that Persona is decommissioned, we will provide at least 9 months of notice, so there are no actions that need to be taken right now. Persona continues to be monitored and supported, though there is still no new feature development. I'm part of the team that runs the production service of Persona, and I can confirm it is operated, monitored and managed like any other critical production service today.
- deno 11y agoI’m sorry, wasn’t my intention to spread FUD.