9 ms·
Identity/Persona Shutdown Guidelines for Reliers
- onli 10y agoShameless plug: Portier is a FOSS project to replace Persona, https://portier.github.io/ https://portier.github.io/. We also just had our time on the HN frontpage, https://news.ycombinator.com/item?id=12837669 https://news.ycombinator.com/item?id=12837669. Lots of questions were answered there, but feel free to ask here as well if anything is unclear.
- captainmuon 10y agoThis is pretty cool, I might try it one day if I build a site that needs login. But this is a lot different than Persona, right? Portier is passwordless login via email (with special handling for Gmail), whereas Persona is another of those "Log in via" buttons (simply speaking)?
- onli 10y agoI'd see it a bit differently, even if in practice you are right, at least the moment Persona added an account system. But also persona had the core idea that you get authenticated by proving that you control the email address entered, see https://developer.mozilla.org/en-US/Persona/FAQ#How_does_Persona_verify_a_user%27s_association_with_an_address https://developer.mozilla.org/en-US/Persona/FAQ#How_does_Per.... On top of that there was the browserid API. Portier is passwordless login via email, with optional special handling right now only for Gmail, yes.
- k__ 10y agoSo how is the workflow? 1. Click "Login with Portier" 2. Enter email 3. Click on link in email 4. Be logged in ?
- kosinus 10y agoPretty much! 1 and 2 are typically a form on the site using Portier (relying party). There's also less emphasis on branding; as a user you will rarely see Portier mentioned.
- onli 10y agoPretty much, yes. However, ideally you would not "Login with Portier", you would simply "Login". There is no need to mention the infrastructure used (and in our current modules, we simply generate a plain Login-Form without any branding). You also do not have to click on the link, you can enter the code which is in the email. Useful when mixing clients. And finally, when using a email provider with special support (currently: Gmail) you don't click on the email and also don't get one. You just login via Google-Sign-In and get then redirected to the site you are trying to login to. I hope we can support more providers (and custom domains soon). Not having to go into the emails is pretty nice. Edit: Also see https://github.com/portier/portier.github.io/blob/master/Design.md https://github.com/portier/portier.github.io/blob/master/Des... for a more technical view on what happens here.
- wofo 10y agoThis is awesome! You automatically get sign in with Google and (in the future) other providers!
- callahad 10y agoExactly! And you can run one instance for all your projects, regardless of language, instead of having to set up Django-All-Auth for one and Ruby OmniAuth for another. Plus, if we can succeed at the federated discovery protocol part, users gain the ability to host their own authentication endpoint that Portier will automatically delegate to.
- deleted 10y ago[deleted]
- zimbatm 10y agoWould be it be possible to support a `.well-known/portier` to support arbitrary SSO?
- fiatjaf 10y agoNo. They work pretty much the same, except Portier is stateless, and Personal needed you to create an account before use, which was unnecessary. Persona also had special handling for Gmail. Portier will probably add more "special handling" cases in the near future.
- onli 10y ago> Portier will probably add more "special handling" cases in the near future. We certainly currently intent to.
- WorldMaker 10y agoPersona only required you to create an account if your email provider didn't support it (or your custom domain doesn't delegate it) or they didn't have special handling for your email provider. There was a bunch of confusion about this early on because a lot of potential early adopters were generally geeks like us who have our own email domains and didn't automatically fall into the special handling (which Persona supported Gmail and Yahoo, which remain the two largest email domains).
- callahad 10y agoTechnically, you always created an account when you used Persona. Sometimes with a password, sometimes without. Sometimes old passwords would come back to haunt you if your domain added and then removed support for BrowserID. Sometimes you would accidentally set up two accounts, because you added a new address to the Persona UI in the wrong order. Sometimes addresses would mysteriously bounce between Persona accounts, because we updated the address/account association on each use. Sometimes you needed a password and sometimes you didn't for the same address, because we supported un-decentralizing Persona on a per-website basis. ...the account story in Persona was way more complicated than it should have been, mainly stemming from the notion that per-login email confirmation loops were too onerous to be viable, and from the idea that users wouldn't succeed with Persona unless it remembered and displayed all of their email addresses in a consistent, persisted account chooser.
- kibwen 10y agoIf you're a fan of the idea behind Persona, it looks like there's a spiritual successor from some Mozilla veterans called Portier, which can be self-hosted (and is written in Rust, if that's your thing :P ). Recent announcement and HN discussion here: https://news.ycombinator.com/item?id=12837669 https://news.ycombinator.com/item?id=12837669
- Flimm 10y agoThe main thing I was keen about was browser integration, which only the browser vendors could provide.
- reitanqild 10y agoCouldn't it be done as a Firefox extension?
- anc84 10y agoYes, but adoption would a tiny fraction of mainline support/promotion could accomplish.
- reitanqild 10y agoLate reply, but: I think this is one of a few areas where a browser or extension developer can create something that will force every other browser vendor to adapt, sooner or later. Last time I feel that happened was with tabs, so IMO this should is a high-value target even if nobody seems to be interested ATM.
- deleted 10y ago[deleted]
- callahad 10y agoPersona was many things to many people -- arguably too many -- everyone from the old core team has a different idea of what features defined Persona. :) For me, it was the developer experience: trivial setup, email in/authentication out workflow, and no secrets to store in a database. Portier focuses narrowly on making that facet work well. Browser integration, identity aggregation, and privacy from users' own email providers are all non-goals for Portier: https://github.com/portier/portier.github.io/blob/master/Non-Goals.md https://github.com/portier/portier.github.io/blob/master/Non... That said, I'd love to ask what you found compelling about Persona's promise of browser integration. The privacy aspects? User experience? The finality of a standard successor to HTTP Basic / Digest authentication? Something else entirely?
- luso_brazilian 10y agoPrevious discussion of the original announcement (Jan 2016): https://news.ycombinator.com/item?id=10884893 https://news.ycombinator.com/item?id=10884893 A decentralized way to authenticate users securely and privately would be an exceptional addition to the open internet. Unfortunately in this case the financial incentive and favors those building "information silos" where the purpose is information collection for profit. I wonder if SMTP would ever see the light of the day with the current mindset as opposed to a "Facebook Messenger"-like multitude of services, much like what happened with the IM fragmentation.
- Flimm 10y agoSuch a shame. Persona was a hugely exciting project. It always disappointed me that Mozilla never fully implemented the vision of Persona integration in the browser, and it puzzles me that Mozilla seem surprised that Persona didn't get much adoption. I still think there's potential for improving user authentication in a way that's usable, privacy conscious and fast, without a costly shim service like persona.org. Maybe Firefox could finally implement the Persona API in the browser for sites to use?
- aestetix 10y ago"Why is persona.org being shut down? Our metrics show that usage of persona.org is low, and has not grown over the last two years. Hosting a service at the level of security and availability required for an authentication system is no small undertaking, and Mozilla can no longer justify dedicating limited resources to this project. We will do everything we can to shut it down in a graceful and responsible manner." I find this a bit confusing because citing low usage and lack of growth is something I'd expect to hear from a for-profit corporation, not a well funded non-profit. Have they shared information on how expensive it is to maintain Persona? I'm also unaware of any pledge drives to get funding for it.
- kchoudhu 10y agoJust because they aren't running it for profit doesn't mean they don't have a bottom line. The additional effort to run a pledge drive is probably not worth the administrative overhead.
- aestetix 10y agoCompletely agreed. This is why I am curious for more information. I'm a big fan of Persona, and very sad to see this happen.
- callahad 10y agoPersona had grown into a gigantic, unmaintainable, big ball of mud. If I recall correctly, the ongoing operational expenses were in the very low 5-figures annually, but it was bitrotting, we weren't able to transition Persona to community ownership, and we couldn't convince Mozilla to reinvest. Which is fine -- I think Persona tried to do too much, and came with too much legacy baggage -- but it left us in a place where shutting it down was the most responsible course of action. Unmaintained critical infrastructure is bad news. I'll be presenting a keynote on this topic at linux.conf.au in January, which should hopefully add some nuance around it.
- aestetix 10y ago
- captainmuon 10y agoI tried Persona back then when it was new, and found it pretty confusing (as a user). Still, it feels like a lost opportunity that it is shutting down. Can someone tell, in a nutshell, what the difference was between OpenID/OAuth (I mean whatever the heck it is that allows me to "log in using my Google/Facebook/GitHub account". I always mix up those two.)? Is it just that you use your e.g. Gmail or other third party email address, but then the authentication is not done by your email account provider, but by Mozilla?
- Flimm 10y ago╔════════════════════════════════════════╦═══════════════════════════════════════════╦══════════════════════════════════════════╦════════════════════════════╗ ║ ║ Persona with browser and email server ║ persona.org shim ║ OpenID ║ ║ ║ integration ║ ║ ║ ╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣ ║ User identifier ║ email address ║ email address ║ URI ║ ╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣ ║ Auth provider ║ Email server ║ persona.org ║ OpenID server ║ ╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣ ║ Passwordless ║ Just one password for your email server ║ One for the shim, and one for your email ║ One for your OpenID server ║ ╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣ ║ Provider sees where you log in ║ No ║ No ║ Yes ║ ╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣ ║ Provider must stay online at all times ║ No, auth tokens are cached ║ No, but persona.org must stay online ║ Yes ║ ╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣ ║ Requires Javascript ║ Yes ║ Yes ║ unknown ║ ╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣ ║ Fallback available ║ Yes, just use the email ║ Yes, just use the email ║ None ║ ╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣ ║ Ability to contact user ║ Yes, just use the email ║ Yes, just use the email ║ None ║ ╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣ ║ Implemented ║ In no desktop browsers or email providers ║ Yes ║ Yes ║ ╚════════════════════════════════════════╩═══════════════════════════════════════════╩══════════════════════════════════════════╩════════════════════════════╝
- natuac 10y agoThe fact that they keep throwing money at useless stuff like that new design for their logo, while at the same time they refuse to keep useful services online, is a clear sign of the downfall of the Mozilla Foundation.
- josho 10y ago> refuse to keep useful services online The project failed to gain widespread adoption. An org that runs marginally valuable side projects indefinitely is an org that is going to face a downfall. Like you, I'd love to see a better authn mechanism, but Persona wasn't going to be it. So, this frees their resources to focus on what is going to continue making Mozilla relevant. Certainly a declining user base on Persona wasn't going to be it.
- Flimm 10y agoMy opinion is that Persona was still untested, we will never know whether Persona was going to be it or not because they never launched the browser integration.
- jamesgeck0 10y agoThey bailed out after failing to displace the most ubiquitous form of authentication in three years. They didn't even have it implemented on their own site for the first six months, and they never built the browser chrome component that would have made Persona appealing to users. It kinda feels like they gave up before they really got started.
- krmbzds 10y agoPersona was a great service. Such a shame.
- phkahler 10y ago>> Identity/Persona Shutdown Guidelines for Reliers I can't parse this headline. It sounds like a weird psychological problem of some sort ;-)
- JadeNB 10y agoYeah, this one https://news.ycombinator.com/item?id=12862355 https://news.ycombinator.com/item?id=12862355 is weird too. I think it's "((Identity/Persona Shutdown) Guide) for Reliers", i.e., a guide to the shutdown of Identity/Persona for people who rely on Identity/Persona.
- creeble 10y agoBecause "Reliers" is a non-word? Non-English word anyway.
- barkingcat 10y agoposted in wrong thread!
- callahad 10y agoI think you mean to be in this thread: https://news.ycombinator.com/item?id=12861815 https://news.ycombinator.com/item?id=12861815
- barkingcat 10y agooops you are right!