4 ms·
This seems to be a nice solution if you are on your own home/work computer and have your email open. They didn't really explain much on HOW it works but the pro
by BryanB55 14y ago
This seems to be a nice solution if you are on your own home/work computer and have your email open. They didn't really explain much on HOW it works but the problem I'm seeing is that if I am at a public computer and want to login I have to log in to my email account first and click on the persona link. I guess the benefit here is that I only need to remember 1 password (my email address password) but my email password is usually a 50 character random string that I don't like entering on public computers if I even could.
So if I want to log in to a crossword puzzle I almost feel like I have to compromise my email password which is much more valuable, if say the public computer has a key logger or something.
Maybe I'm over thinking. I could see how this would be useful if I have my desktop mail client running and just click a link to log in though.
- ThaddeusQuay2 14y ago"my email password is usually a 50 character random string that I don't like entering on public computers if I even could" "I almost feel like I have to compromise my email password which is much more valuable" I understand your concern. I suggest using either two-factor authentication (such as Google's) or creating a "throwaway" email account just for this purpose.
- deleted 14y ago[deleted]
- zerostar07 14y agoThen you would not use your primary "super secure" email as your browserId, but a secondary mail account.
- loumf 14y agoThe most valuable thing about your email account is that it's your password recovery mechanism. What ever email account you use for password recovery or logging into things becomes the "super secure" email account. There is no message in my email that I care more about than the one that might give you access to my bank accounts.
- JakeSc 14y ago> There is no message in my email that I care more about than the one that might give you access to my bank accounts. This is very well phrased. Email sort of serves two purposes these days, each with very different security models: text-based communication, and external service authentication. Do you have any ideas for separating these two functions, or at least improving their security?
- loumf 14y agoNot really. The main thing that has been happening over time is that more and more low-security messages are being drawn away from email (Twitter, FaceBook, SMS). I used to get email forwards from friends/family -- now they post to FB. I never get a pic emailed to me any more. So, the trend to separate out low-security messages has been happening -- perhaps trending towards leaving email as only a password recovery mechanism. Or maybe not even that -- I use 2-factor for Google and FB -- where SMS is in the mix -- SMS could even be the recovery mechanism, moving even those messages out.
- zerostar07 14y agoPasswords are not the only authentication option. This could be a good way to replace all your passwords with something stronger (2 way, fingerprints, you name it) if your provider supports them.
- icebraining 14y agoThat's what two-factor auth is for.
- stdbrouw 14y agoThat's not really how it works. You verify your email address once, and after that you can just log in with your address and password. You don't have to click on an email link every single time you log in.
- deleted 14y ago[deleted]
- StavrosK 14y agoYou can have a provider that requires no auth. Try entering whatever@mockmyid.com as an address.