4 ms·
I'm very sad to see this announcement. I've been a big fan of persona since I first learned about it three years ago, and for a few months I tilted at windmills
by jbclements 11y ago
I'm very sad to see this announcement. I've been a big fan of persona since I first learned about it three years ago, and for a few months I tilted at windmills by writing to services I used, and asking them why they didn't support persona login.
After writing about four of these, though, I had a small epiphany; this is a ludicrously uphill battle, because Facebook and Google don't just make it easy to use their login because they're nice; the information that they gather from these logins is worth good money to them, and so of course facebook+google login is the most frictionless and butter-easy way to implement login.
Sigh.
Okay, I know this was totally obvious to everyone but me, but it does make me sad, and I can start to see the outlines of an internet that I'm somewhat less excited about than the one we have now.
I'll miss you, persona. Mozilla, keep up the good fight!
- iheartmemcache 11y agoI was an early adopter of OpenID and still lament the loss. I'm familiar enough with Persona and IdP's that I could probably fork I'm flirting with the idea of offering LTS out-of-pocket as a public service if there is enough backing [e.g. demand by the geek community. Decentralized authentication is important and I feel strongly enough to engineer for free and/or offer corporate support through my corporation for Persona and use it to subsidize additional development]. I also am working on offering both a FreeDNS service with DNSsec both as an authoritative server for all end-users (services like GoDaddy mark this, as well as SSL certificates, as a "premium service" and that is sheer insanity; I have made it my personal goal to ruin services like this and "SSL watchers" which charge 20$/mo to ensure your cert doesn't expire). Also don't use OpenDNS, not only do they inject ads, but they break DNS by stripping DNSsec which is both unethical and a violation of the spec. I'll have a blog post up on that later this week. If you have a web-site, don't have shell access but still want to put a cert up, https://www.sslforfree.com/ https://www.sslforfree.com/ use these guys. They'll authenticate your ownership the same way Google Analytics does, then you associate the cert with your domain in the same way you would had you bought it from VeriSign. [0] https://www.surveymonkey.com/r/VLFM7FD https://www.surveymonkey.com/r/VLFM7FD - please fill this out if you have either interest in Persona or that DNS service I mentioned (the latter of which is likely to go up this week, the former depends on demand)
- StavrosK 11y agoA few people and I have been talking about Persona and possibly developing a next version, we're chatting on https://gitter.im/letsauth/LetsAuth https://gitter.im/letsauth/LetsAuth, or #letsauth on Freenode. Feel free to join either, we'd love to brainstorm together.
- greggman 11y agoPartner with auttomatic (Wordpress). They're open source and apparently 25% of the web is run on their software. Could be a good jump start ?
- StavrosK 11y agoThat's a fantastic idea. Definitely something to keep in mind for potential integration, thank you.
- fiatjaf 11y agoFor interested people, it ended up with https://github.com/letsauth/letsauth.github.io/wiki/Roadmap https://github.com/letsauth/letsauth.github.io/wiki/Roadmap
- WorldMaker 11y agoI like the idea of maybe pursuing a extension-first plan for the next attempt at BrowserID. Some thoughts: - There have been Persona extensions before for at least Firefox. It will probably be important to learn from them, even if I'm sure hardly anyone tried to use them. - Edge's extension support can't come soon enough. - The issue I could see with extensions is it is harder to trust the verified email addresses in "fallback" situations. The chicken and egg bootstrap problem here still seems to indicate that you still want some sort of trusted notary. Maybe a simpler fallback provider that is just a state-less "passwordless" (passwordless.net) proxy that would be easy to clone and some way to create an actively maintained whitelist of trustworthy clones? - While we're looking at "extension-first", maybe find ways to make use of the browser's SSL client certificate infrastructure? Obviously, if you could build a good UX for bootstrapping (email-only) client certificates you could finally help people make good use of such an old, underutilized browser feature.
- VeejayRampay 11y agoWith APIs that change arbitrarily, inconsistencies in the different implementations, tokens that expire after a few months for no good reason, I wouldn't exactly describe the social login experience as frictionless and butter-easy. YMMV though, maybe I'm not approaching the social login from the right angle, I don't know.