23 ms·
New Persona Beta: Millions of Users Ready to Log In using Any Browser
- TomGullen 13y agoI do see the huge potential benefits of the system but have a couple of concerns. I'm concerned that a 'one password' for everything can be more of a liability if your password is stolen/lost and make phishing potentially more lucrative. Also concerned about a centralised password store - people make mistakes and if there was some DB leak/hack it could be damaging as it would not be contained within one system (if I've understood how it all works correctly).
- menny 13y agoPersona should add two-factor authentication. For that matter, any open-ID or similar technology should add that.
- AndrewDucker 13y agoPersona is only handling authentication temporarily. Once email providers start providing their own Identity Providers then the security falls entirely on them. For instance, once GMail starts being its own authenticator, my two-factor authentication there will kick in.
- callahad 13y agoIdentity Bridging will eventually get 60-80% of users functionally off of our fallback and onto their provider's native authentication paths, but I do wonder if the Persona fallback support two-factor auth natively for the remaining 20-40% of users. Thoughts?
- TheCoelacanth 13y agoPersona leaves authentication entirely up to the identity provider. In the case of the fallback identify provider that you're probably seeing, they choose passwords. Other identify providers can choose any method of authentication that they want to use.
- dochtman 13y agoThat's just the fallback identity provider Mozilla runs. The idea is that your GMail address will authenticate you using whatever GMail uses, so you can use 2-factor authentication. If you have your own domain/server, you can easily switch out password authentication for something else today if you run your own Identity Provider. Here's my minimal Python IdP implementing TOTP (Google authenticator) authentication: https://bitbucket.org/djc/persona-totp https://bitbucket.org/djc/persona-totp
- brianjyee 13y agoThere has to be at least one password. If you use password managers like Lastpass or Keepass, you're essentially putting all your eggs in one basket, but that is generally safer than what the typical internet user does which is use the same password for everything.
- AndrewDucker 13y agoPersona is decentralised by design (with a centralised stop-gap to get things going). Once other companies implement their own Identity Provider it's all entirely decentralised.
- drivingmenuts 13y agoDoesn't that lead to the problem of having to have multiple identities again? ATM, I have a FB account that I can use to log in to some sites, a Twitter account, a Google account, a Yahoo account, etc. With potentially everyone being able to be an Identity Provider, what happens if a site recognizes some providers, but not others? Does Persona ensure that, regardless of Provider, I can use one login on all sites? Furthermore, how does it protect me from the site gathering and aggregating all kinds of information about me (which, admittedly, they probably already have)? There's usually one overarching, way-behind-the-scenes entity handling the data aggregation for many sites (ie., Facebook) which leads us right back to where we are now. Or is that part not addressed by this solution?
- TheCoelacanth 13y agoPersona is the protocol that the sites use to communicate with the identity provider. If they support Persona they will support Persona authentication from any email provider that chooses to support Persona and from the fallback provider that Mozilla provides.
- unhammer 13y agoWell, since they get the email address, they can easily check that it ends in @gmail and stop everyone else. Of course, only supporting gmail means they have to write _more code_ than supporting every provider, so lets hope lazyness wins.
- ddlatham 13y agoFor most people, their email password already is 'one password' for everything. If someone compromises their email account then they can use the account recovery features of these other websites to reset their password through email.
- alexangelini 13y agoDoes this work yet with Chrome on iOS? The last persona enabled web site I tried, simply threw an error when using the Chrome app. EDIT: Here is a link to the progress on this issue, it was moved to the next beta https://github.com/mozilla/browserid/issues/2034 https://github.com/mozilla/browserid/issues/2034
- AndrewDucker 13y agoHere's the list of supported browsers: https://developer.mozilla.org/en-US/docs/Persona/Browser_compatibility https://developer.mozilla.org/en-US/docs/Persona/Browser_com...
- artursapek 13y agoWhy are they shitting on social sign-in when this works the exact same way, but with email providers? You still need a pop-up that takes you to several domains and makes you click Yahoo's "Accept" button. I can see the confidence people might get from the added layer of Persona talking to the external service as opposed to the website that you've never been to before (given the Persona brand builds lots of trust), but the UX is still just as clunky and awkward.
- jordan0day 13y agoThe UX isn't perfect, but Persona does have a few advantages that ultimately make it better for the end user: 1) Doesn't require a popup. The idea with Persona is that browser developers would build a Persona/BrowserID-type dialog directly into the browser, as opposed to requiring a popup/webpage. This may help mitigate phishing. 2) Better privacy for the end user. With other, uri callback-based systems, your IdP's know what sites/services you're accessing. With Persona, this becomes a bit more difficult, as there is no callback mechanism.
- ozten 13y agoDirectly from the article: Julius Schorzman of DailyCred, the instant CRM package for any web site, implemented Persona and remarked “We’ve seen from our internal metrics that more than 70% of users still prefer email and password authentication over social log-in like Facebook. Implementing Persona is actually easier than Facebook Connect, or any OAuth implementation we’ve seen.” People want control over their identity on the web. Social sign-in doesn't meet this need.
- cinquemb 13y agoI'm personally not a big fan of social sign in, and i doubt i'm going to use persona (at this time). Persona seems like to me kinda like what the chinese are doing with requiring people to use .gov ids on the web. Sure in china it will be by force and here it will be opt in, but in my eyes the result will be the same: making it easier to track people across the web. I don't feel like persona solves the ability for a person to have control over their identity on the web any more than people do now, maybe just offer the same utility of social logins without trusting 3rd party(?). Are all persona users data stored in a central location (besides websites that have multiple users sign up through persona?)
- troyinjapan 13y agoWhen it works with Gmail, then the world gets better.
- mixedbit 13y agoIt already works with any email address, including Gmail. But the Persona team works on a dedicated support for Gmail, that will allow Gmail users to use Persona without a need of an additional password.
- callahad 13y agoThough we might need a month or two to get a few last details ironed out, an identity bridge for Gmail is absolutely coming soon. Until then, we wanted to soft launch with a single bridge (Yahoo) before throwing the switch for everyone.
- NelsonMinar 13y agoPersona seems terribly important. And well designed, particularly compared to the ad hoc social login systems. I don't understand why it doesn't have more mindshare. Is it not yet ready for use by consumer sites?
- lazyjones 13y ago> I don't understand why it doesn't have more mindshare. Because all they've published so far is API specs and fluffy PR sites that try to portray it as "oh so much better" without offering any insight about why it is better. They can claim "more privacy" all day long, but without any details about what gets stored where and why it is supposed to be safer, they don't make a compelling case. Look at this page for example: https://login.persona.org/about https://login.persona.org/about (the "how it works" page) - it has 0 details about these claims and unfortunately, we're already tired of reading how Google and FB respect our privacy. From "outside", it looks like we need to give Mozilla our (existing) credentials and trust them to handle them with care. Why should we? I feel safer making pwgen passwords for every new site I need to register at.
- bzbarsky 13y agoEr... "they" have also published the full source code involved (at https://github.com/mozilla/browserid https://github.com/mozilla/browserid ) and a privacy policy at http://www.mozilla.org/en-US/persona/privacy-policy/ http://www.mozilla.org/en-US/persona/privacy-policy/ that you can compare to said source code as desired, if you're using Mozilla's identity provider. As far as the architecture of the overall thing, there are also http://identity.mozilla.com/post/7899984443/privacy-and-browserid http://identity.mozilla.com/post/7899984443/privacy-and-brow... and http://identity.mozilla.com/post/11145921163/browserid-design-for-privacy http://identity.mozilla.com/post/11145921163/browserid-desig... and a technical specification at https://github.com/mozilla/id-specs/blob/prod/browserid/index.md https://github.com/mozilla/id-specs/blob/prod/browserid/inde... that describes the exact data flow involved. And if you read those, it should become pretty clear _why_ this is better for privacy than the FB or Google login systems. For one thing, the identity provider is never told that you're logging in.
- huhtenberg 13y agoPlease, guys, change the pastel orange background of the blog to something a bit more serious. It gives wrong first impression and starts things off the wrong foot.
- riquito 13y agoBlue or grey may be better suited to you? https://developer.mozilla.org/en-US/docs/persona/branding https://developer.mozilla.org/en-US/docs/persona/branding
- huhtenberg 13y agoI was referring to #FFFBED of the blog background.
- davecap1 13y agoI like Persona a lot and I would love to implement it on some of my sites, but I wonder how to best describe what it does to the average user. "Sign in with Persona" will probably look just as bad as "Sign in with Facebook"...
- AndrewDucker 13y agoI'm working on implementing it myself right now, and mine just says "Sign in" (albeit with their design). If they recognise it, then they'll know. If they don't, then they don't need to.
- ozten 13y ago"Sign in with your Email" is pretty clear. via https://developer.mozilla.org/en-US/docs/persona/branding https://developer.mozilla.org/en-US/docs/persona/branding
- davecap1 13y agoAh thanks for that
- callahad 13y agoThree possible approaches, from most to least verbose: 1. http://sloblog.io/login http://sloblog.io/login has a nice, explanatory landing page. 2. https://www.voo.st/ https://www.voo.st/ has a small string of explanatory text at the point where a user chooses between Facebook or Persona auth. 3. http://crossword.thetimes.co.uk/ http://crossword.thetimes.co.uk/ has a simple, unbranded "log in" button that just opens the popup.
- jakub_g 13y agoCan someone recommend a good article about how Persona exactly works under the hood? I've seen zillions of news about Persona but haven't grasped the main concept. Comparison with OpenID will be appreciated also. Many of articles say that Persona is great and awesome etc. but do not explain what are the advantages and security implications.
- 6a68 13y agoHere's a medium-level technical overview: https://developer.mozilla.org/en-US/docs/Persona/Protocol_Overview https://developer.mozilla.org/en-US/docs/Persona/Protocol_Ov... If that's not geeky enough, you can read the spec for the browserid protocol: https://github.com/mozilla/id-specs https://github.com/mozilla/id-specs Comparison to OpenID is covered in the FAQ page: https://developer.mozilla.org/en-US/docs/Persona/FAQ#How_does_Persona_compare_to_OpenID.3F https://developer.mozilla.org/en-US/docs/Persona/FAQ#How_doe... We've got a list of recent talks, too, in case you'd rather flip through slides or watch a video: https://wiki.mozilla.org/Identity/Spread_Persona https://wiki.mozilla.org/Identity/Spread_Persona
- ecaron 13y agoIf you're looking under the hood, the mechanic's blog at http://lloyd.io/how-browserid-works http://lloyd.io/how-browserid-works offers a great explanation. The Mozilla blog covered the OpenID comparison at http://identity.mozilla.com/post/7669886219/how-browserid-differs-from-openid http://identity.mozilla.com/post/7669886219/how-browserid-di..., but it doesn't embrace the level of geekery you're likely seeking.
- kibwen 13y agoHow it works under the hood: http://lloyd.io/how-browserid-works http://lloyd.io/how-browserid-works Comparison to OpenID: http://identity.mozilla.com/post/7669886219/how-browserid-differs-from-openid http://identity.mozilla.com/post/7669886219/how-browserid-di...
- abhinavg 13y agoThis is off the top of my head so maybe somebody will correct me, but: Persona is a login system that cares about your privacy. With social login systems, the website you are logging into contacts the social login provider (Facebook/Google+/Twitter/what-have-you) when you attempt to log in. So you end up leaving a trail of breadcrumbs behind you of every site you visited (and used a social login on). Further, many people are not comfortable giving sites access to their social accounts because of privacy concerns. With Persona, the idea is that your identity provider (can be your email provider, persona.org , or someone else) will have a key publicly available on their site. Your browser would generate a certificate that can be verified against that key. However, since the same key from the provider is used to authenticate all accounts on that provider, all the provider finds out when a website contacts it for the key is that someone is trying to log into said website. Plus, the website could cache the certificate and now the provider does not know this either. There is more to this so you're probably better off reading one of the other links.
- daphneokeefe 13y agoSo I can log in everywhere using the exact same username? This will make it SO much easier for the user data trackers to capture and aggregate all of the information they can about me. I think I'll take a pass.
- ozten 13y agoYou can choose any email address you control. Persona doesn't force you to use one identity. Sites that use Facebook connect on the other hand...
- deleted 13y ago[deleted]
- jordan0day 13y agoThis is a legitimate concern. It's also one that isn't very easy to solve, regardless of how you slice it. Most sites that let you create your own username still require an email address. If you're using the same email address, we're back to square one here. Persona absolutely does not increase your trackability, and by giving users at least the option to use multiple, different email addresses, it's better for privacy than, say, Facebook Connect. That's a win in my book.
- deleted 13y ago[deleted]
- bzbarsky 13y agoOne major difference is that if you log in to a site with Facebook then Facebook knows you logged in to the site. Whereas if you log in to a site with Persona, that's between you, your browser, and the site. Mozilla is not pinged with any details about you in the process. Furthermore, Persona is decentralized. Anyone can run an identity server (though sites don't have to trust all servers, obviously). So you do not in fact have to build an account with anyone new if your mail server deploys Persona and sites trust it to identify people. The article points out the Yahoo has rolled this out already, so anyone with an @yahoo.com mail doesn't have to do any new account-building.
- ecaron 13y agoBefore they push Persona more, can someone walk over to the team that's running http://www.getpersonas.com/en-US/ http://www.getpersonas.com/en-US/ and either disconnect their servers or lock them to their chairs until they finish the migration? I understand the pain of rebranding assets, I do. But if you're going to rebrand to a product your company is already using, it has to be fast. And Mozilla, the 2 year anniversary is in July...
- at-fates-hands 13y agoCompletely agree. When I first starting hearing about it, this is what popped into my head. For the longest time, I couldn't separate the two. At the very least, they should have chosen a different name.
- potch 13y agoThe migration is actively underway! The site will be shut down in a time scale ordering on weeks.
- potch 13y agoCorrection, getpersonas.com is now decommissioned!
- callahad 13y agogetpersonas.com is currently read-only [0], "Personas" have been renamed to "Themes" on addons.mozilla.org [1], and the getpersonas.com domain should go away within two weeks [2]. [0]: https://blog.mozilla.org/addons/2013/03/27/getpersonas-com-is-becoming-read-only/ https://blog.mozilla.org/addons/2013/03/27/getpersonas-com-i... [1]: https://addons.mozilla.org/en-US/firefox/themes/ https://addons.mozilla.org/en-US/firefox/themes/ [2]: https://blog.mozilla.org/addons/2013/02/28/getpersonas-com-migration-update/ https://blog.mozilla.org/addons/2013/02/28/getpersonas-com-m...
- callahad 13y agohttps://getpersonas.com https://getpersonas.com is now dead.
- lifeformed 13y agoCan I associate additional data to my profile? A lot of websites I use want to know my name, nickname, age, avatar-pic, timezone, etc. It would be nice if I could store it all with my Persona account and selectively allow access to sites that request it. I could even store my credit card info, and when the site wants me to fill in my address and such, I just click to allow access to that data, which can then autofill the forms. I could even add things like have browsing preference data like "prefers-dark-on-light-theme", "no-video-or-audio-autoplay", or "no-nsfw-content". The site can add functionality for these preferences if it chooses to. Does Persona already have this?
- ozten 13y agoNo, we don't currently provide any profile information. We'd love to see more experiments in this space. Get involved https://github.com/mozilla/browserid https://github.com/mozilla/browserid
- OoTheNigerian 13y agoHere is my feedback. Perhaps the marketing of "persona" to consumers should take a backseat. When I signed in to http://123done.org/ http://123done.org/ the pop up* showing "sign in with persona" confused me for a moment. For a moment, I thought.. "but I do not have a persona account" If there is a way for users to just sign in with their email without telling them how it is done, I am sure there will be even less friction. Of course, the persona architecture could still be marketed to developers for integration purposes. But for users, let it just be like magic. PS: I did not see the Firebase implementation they spoke of. I am still told to make sure my password has 8 characters. https://www.firebase.com/signup/ https://www.firebase.com/signup/ *https://www.dropbox.com/s/4ay0qp434rqd0dm/persona.png https://www.dropbox.com/s/4ay0qp434rqd0dm/persona.png
- alefteris 13y agoRegarding Firebase, they said that they "added support for Persona as one of the authentication mechanisms for their Simple Login service". Their main website must not be using this service or not enabled the particular authentication component?
- anant 13y agoThat's correct, the Simple Login service allows apps that use Firebase to integrate Persona authentication: https://www.firebase.com/docs/security/simple-login-persona.html https://www.firebase.com/docs/security/simple-login-persona.... This means the data you store in Firebase can be associated with a Persona user, and you can structure your security rules to enforce whatever read/write behavior makes sense for your app.
- riquito 13y ago"sign in with persona" may be confusing now but "sign in with your e-mail" it's pretty clear https://developer.mozilla.org/en-US/docs/persona/branding https://developer.mozilla.org/en-US/docs/persona/branding
- huhtenberg 13y ago
- macspoofing 13y agoI have to say that I'm really loving Mozilla/Mozilla Research these days. Their heart is in the right place, and their research projects like Asm.js, Persona, Rust, and Firefox OS are very cool. They are what Google was in 2005.
- 6a68 13y agoAw shucks, thanks! Unlike Google in 2005, Mozilla is a non-profit actively working to protect user privacy & build a better web. Also, everything we build is open source :-)
- PommeDeTerre 13y agoRust is perhaps the only thing that you listed with any real promise. It is bringing in some good ideas from other programming languages, and it does appear to be a language that may eventually offer some practical value. Asm.js is, at best, a very ugly hack. Instead of going in the right direction and eliminating JavaScript in favor of a proper embedded runtime or virtual machine, it's just promoting further use of bad (even if widespread) technologies. Firefox OS doesn't appear to be anything but a me-too catch-up effort. Nothing suggests it can truly compete with iOS or Android, never mind the numerous other mobile OSes out there that are available on far more devices and actually have at least some users. Persona is perhaps a good-hearted effort, but it's pretty clear that it isn't catching on. There are already too many other authentication systems out there, and many of them have far more traction. The community as a whole would likely get much better value if Mozilla focused on the software that many people actually use on a daily basis, like Firefox and Thunderbird, rather than these side projects that don't really offer much at all.
- callahad 13y ago> Persona is perhaps a good-hearted effort, but it's pretty clear that it isn't catching on. This is news to the Persona team.
- PommeDeTerre 13y agoThat's unfortunate to hear. I would have hoped that you'd be more aware of its actual level of adoption. Taking an objective look at the situation, as somebody who isn't tied to the project, I just don't see it being used. While so many web sites and applications allow authentication using Google, Facebook, Twitter and even some other more obscure providers, I never see Persona listed as an option. The adopters listed in the article are minor, at best. Given that the BrowserID initiative has been public for almost two years now, it's not a very impressive list. It's easy to write blog articles claiming that "hundreds of millions of Web users are now ready to log in with just a few clicks", but we just don't seem to be seeing that actually happening in practice.
- scragg 13y agoI tried to log in to this site https://current.trovebox.com/ https://current.trovebox.com/ which was linked on the Persona home page: http://www.mozilla.org/en-US/persona/ http://www.mozilla.org/en-US/persona/ I tried to use my gmail address and it gave me this: http://dl.dropbox.com/u/13941904/persona.png http://dl.dropbox.com/u/13941904/persona.png Am I just making up a password for a Persona account and it's using my email address as the user id? I can see how some people would type in their gmail password in by mistake.
- ozten 13y ago> Am I just making up a password for a Persona account and it's using my email address as the user id? Yes, gmail isn't a Persona identity provider, so we have to create an account for you. Try logging in with a yahoo email account. You will not have to create a "Persona account" password. The moment Google implements Persona support, we'll stop asking you for this password and delegate to Google's web log in flow.
- lazyjones 13y ago> I can see how some people would type in their gmail password in by mistake. I can see how this could be a big problem once one ID provider decides he'd be interested in grabbing and abusing such credentials. The natural password related to the e-mail address for most people is that of the e-mail provieder.
- unhammer 13y agoI found this bit confusing too, but in a different way. The first time around, I knew I was making up a new password, just not where it would be stored. Then much later I used a different computer (but firefox sync'ed) and tried logging in to Persona, got asked for a password, and thought "oh, so now I make up a new one because it's a new browser and this is BrowserID? Where is this password stored anyway?" I'm guessing that password is stored on persona.org, not in my sync profile, but even after reading http://lloyd.io/how-browserid-works http://lloyd.io/how-browserid-works I still find this one point confusing. EDIT: I now see that the creation bit has a "verify" field whereas the sign-in bit has only one field, I guess that should have been my hint to use the same password as before. I'm still wondering though how it works when you have several email accounts on one browser, do they all share the same password? Does persona.org know that I have all those email addresses?
- kristofferR 13y agoWow, I thought Personas were just stupid themes for Firefox, but this is actually pretty interesting.
- darxius 13y agoI haven't been keeping up to date with Persona, but doesn't this open a window for email account breaching? I can picture some malicious websites mocking the "Sign in with persona" process and gaining the email AND associated password for that account without much trouble. Unless I've misunderstood Persona's point and the password is different from the user's email password.
- ozten 13y agoOur team has thought a lot about this. There are a bunch of angles to answer this from. Short answer (assuming native browser, native webmail provider): The malicious website would have to fake browser chrome and fake the user's webmail login flow. Long answers: Search through the mailing list and get involved! https://groups.google.com/forum/?fromgroups#!forum/mozilla.dev.identity https://groups.google.com/forum/?fromgroups#!forum/mozilla.d...
- darxius 13y agoThanks for the link ozten, I'll definitely follow the mailing list. Cheers on the good work -- I'm sick of entering passwords.
- w-ll 13y agoWhat if I just want to collect emails and passwords, and with a free cert and a funky domain harvest (email, password)'s? I thought the whole point was to be password less? Second, I wanted to play a crossword puzzle. I click login and am greeted with a popup window, I put in my email, then it asks for a password (ok whatever). So now I have to go to my email, and it says that I click the link and can go play the puzzle, but then it takes me to some persona account manager thing. I go back to my email, click the link again, this time with an error an no puzzle :( Whats new here? That you guys plan is to just store logins for people? Do you share my email with the webapp I wanted to use? Seriously, whats new here?
- callahad 13y agoCould you try going back to the crossword and trying to log in? If that doesn't work, it sounds like you hit a bug -- could you file that at https://github.com/mozilla/browserid/issues https://github.com/mozilla/browserid/issues, please? The password stuff was because your email provider doesn't support Persona's protocol, so it fell back to asking Mozilla to validate your identity with a challenge email (and a password, so you don't have to use a challenge email when you come back next time).
- hammock 13y ago> Ting, Tucows’s mobile phone service Off-topic, but wow. Blast from the past. Tucows is still around, and now has a mobile phone service! That was my go-to place for shareware games when I was a youngin'.
- Flimm 13y agoFor this to be adopted, you need to have at least one major email provider implementing it, at least one major browser, and at least one major website. If you don't have the three corners of the triangle, people will inevitably judge Persona by its fallback implementation and will fail to understand the advantages Persona offers. The good news is Mozilla have managed to implement a bridge that makes it look like one major email provider, Yahoo!, implements it. Now you need the other two corners. Firefox OS is not mainstream enough, why doesn't Firefox for the desktop implement this natively yet? Isn't the whole of Mozilla behind this initiative? (Also, why haven't they fully retired the old usage of the brand Mozilla Persona yet?)
- kyrias 13y agoThere's no reason for it to be integrated in the browser?
- jordan0day 13y agoBrowser integration is actually supposed to be one of the core pieces of Persona. The idea is that by building the Persona login process directly into the browser (as opposed to it requiring a popup/webpage) then phishing attacks may be somewhat mitigated.
- Flimm 13y agoThat, and a better user experience. Have a look at this screenshot, doesn't it seem obviously more attractive and usable than a pop-up? http://www.extremetech.com/wp-content/uploads/2011/07/firefox-account-manager.jpg http://www.extremetech.com/wp-content/uploads/2011/07/firefo...
- Flimm 13y agoAlso, it's more private. With a native browser implementation, you don't communicate with persona.org every time you log in to a website, you only have to trust your browser to store your cached authentication credential.
- badida 13y ago
- sergiotapia 13y agoI implemented persona for ASP.Net MVC3 and it was hands down the easiest login system I've ever built in my career. From a developer standpoint it's very intuitive, the documentation is great, and I loved it so much I open sourced my implementation. https://github.com/sergiotapia/ASP.Net-MVC3-Persona-Demo https://github.com/sergiotapia/ASP.Net-MVC3-Persona-Demo Please give this a shot! I would only like them to keep more information on hand, like a first name, or an avatar so I don't pester my user with such requests.
- 6a68 13y agoThanks sergiotapia! Please ping the dev-identity list with your feature ideas, or open a bug on github; our roadmap depends on community input. We have a list of libraries/plugins in a ton of other languages on MDN: https://developer.mozilla.org/en-US/docs/Persona/Libraries_and_plugins https://developer.mozilla.org/en-US/docs/Persona/Libraries_a...
- sergiotapia 13y agoWhere would this github be? Do you mean the browserid repository on Github?
- 6a68 13y agoYup! https://github.com/mozilla/browserid/issues/new https://github.com/mozilla/browserid/issues/new
- groks 13y agoI don't think you've actually implemented the protocol. Like most of the other examples I've looked at, you explicitly check every login attempt with the hard-coded mozilla verifier. This breaks two of the selling features of browserid: 1) Your identity provider doesn't know where/when you login because the relying party (the website) is supposed to cache the identity providers public key. 2) When identity providers start implementing browserid, it's not going to make any difference because you're not checking back with the identity providers website, as encoded in the assertion. What you've implemented here is more like Microsoft Passport - a single point of failure through which all logins flow. So, as a bootstrap mechanism the Persona service fails, because assuming people jump on the browserid bandwagon, we'll still be stuck using Persona because all the websites have implemented the protocol wrong (as in this case).
- dilipray 13y agoSo, openid by firefox is called persona? I would like to use google, twitter. What are the special features of this? I don't think anybody would like to use firefox OS. But it's good, but it has a heavy competition in the future.
- TheCoelacanth 13y ago1. Privacy: the identity provider can't tell what site you are logging in to. 2. It's decentralized: any email provider can provide Persona authentication for the email addresses that it handles. You don't have to rely on Mozilla to do this except as a fallback for email providers who don't support Persona.
- shared4you 13y ago>> type in email, login to yahoo... Wait. So, my email provider (Yahoo) can now keep track of every website I login to, if he wants? How can I stop Yahoo being the middleman? Second question, if an attacker knows my Yahoo password, can he potentially login to _all_ Persona-powered websites with my email then?
- ozten 13y ago> Wait. So, my email provider (Yahoo) can now keep track of every website I login to, if he wants? How can I stop Yahoo being the middleman? Nope. Architectures like OpenID "phone home" and report your movement across the web. Persona was explicitly designed to be privacy preserving. > Second question, if an attacker knows my Yahoo password, can he potentially login to _all_ Persona-powered websites with my email then? Yes, if an attacker has your yahoo email address and password, they can log in as you. BUT, you can take advantage of two factor auth from Yahoo as well as other security features they provide, to keep yourself safe.
- badida 13y agoNo, because Persona mediates, and Yahoo only knows that you're using your Yahoo identity with Persona, nothing more. That's a key privacy property of Persona. However, if you use the "login with Yahoo" button (or Google or Facebook), then yes, they can track all of your activity. To your second point: great question! No, the attacker cannot. We still protect your other email addresses with a Persona password.
- badida 13y agoOh wait, I misread your point. Yes, the attacker can log into all Persona web sites if they know your Yahoo password. But that's the way the cookie crumbles with federated identity. It's the same thing if you pick a Yahoo email address as your recovery email. Pick your identity providers wisely!
- human_error 13y ago> Yahoo only knows that you're using your Yahoo identity with Persona But Yahoo still knows that I'm on that website.
- antninja 13y agoI don't like Persona, personally. Email is not an identity. When we connect with email and passwords, both fields are keys (in the open-the-door metaphor). To make the password a secret key, we can't check it for uniqueness so we need a less secret key that will be checked for uniqueness. I think it's important that users can easily modify both keys without loosing their identity.
- Bjoern 13y agoSorry crawled up from under a stone here. Asked myself how is this different from OpenID, then I found this (fyi). http://identity.mozilla.com/post/7669886219/how-browserid-differs-from-openid http://identity.mozilla.com/post/7669886219/how-browserid-di...
- enygmadae 13y agoIf anyone's curious about using PHP and jQuery to integrate it into their sites, check out this article I wrote up: http://websec.io/2012/10/01/Using-Mozilla-Persona-with-PHP-jQuery.html http://websec.io/2012/10/01/Using-Mozilla-Persona-with-PHP-j... It's got curl and streams examples so it should cover 95% of the PHP installs out there. Its crazy how easy it is to drop in and implement...Mozilla's done a great job with it so far. I look forward to more integration of it in the future.
- ppierald 13y agoThe concept of putting <script src=> on my login page skeevs me out more than a little bit. This is a major security hole that won't be patched until there is native support in the browser.
- badida 13y agoor until we give you a library you can audit and host yourself, which we're working on.
- weisser 13y agoWould Google ever allow this work with Gmail? Since they are trying to get sites to adopt the "sign in with google" option I'm curious if they would get behind this initiative.
- badida 13y agoYou should tell them you'd like them to :)
- mixedbit 13y agoCongratulations to the team, keep up the great work!
- laserDinosaur 13y agoI'm confused - What is the difference between this and sites that let me login with my Google account?
- callahad 13y agoPersona works with any email address, so the major difference is that you can get the "Sign in with Google" experience, with just one button, but without being forced to choose (and phone home to) Google.
- ZirconCode 13y agoAnother big thing is privacy. Signing in with google, or facebook pretty much enables them to stalk you. This can't happen with person due to its architecture =)
- jaredhanson 13y agoThis is fantastic! I'm really excited to see Mozilla improving the login experience for users across the web. It is a problem that is sorely in need of better solutions. For the Node.js developers in the crowd, I'm happy to see Mozilla is using Passport.js (http://passportjs.org/ http://passportjs.org/) (which I'm the developer of) to power the OpenID/OAuth dances when doing identity bridging. You can see it in action at the BigTent repo: https://github.com/mozilla/browserid-bigtent https://github.com/mozilla/browserid-bigtent Passport.js can be used in your own applications to easily perform the server-side part of Persona/BrowserID as well as integrate with or transition from an existing login system.
- ozten 13y agoJared is also a great project maintainer. He has been very responsive to questions and stays on top of github issues. Go Passport!
- pyxy 13y agoSometimes I create accounts with email address like me+thissite@gmail.com. It is handy for filtering emails from thissite later. Will this great feature of email (SMTP?) be available to me with Persona? I mean email address synonyms.
- unhammer 13y agoI already have three such aliases in my Persona account. I'd say Persona makes it easier to use the me+thissite@fastmail.com method. Of course, if you add a hundred such, you'll get a very long list to click through when you log in …
- jokoon 13y agocan somebody explain to me why this is so much better than openid ?
- callahad 13y agoThere are a plethora of links elsewhere in this thread answering that exact question, but in brief, the developer experience, user experience, and privacy model are all dramatically better.
- robert-wallis 13y agoWhy promote Yahoo!'s email service? They still don't use SSL after you are logged in right? Sending your plaintext session cookie over the net, allowing people in your coffee shop to hijack your email. Nobody should be encouraging people to keep or get Yahoo email accounts.
- robert-wallis 13y agoJust checked, you can now enable SSL, but by default it is not enabled. No doubt most people don't have it on. Therefore, Yahoo is still an insecure email service.
- callahad 13y agoWe had to start somewhere, and Yahoo's OpenID endpoint seemed pretty sane. Gmail and Hotmail are coming soon to round it out.
- fiatpandas 13y agoOh neat, it seems my current Firefox (20) works with Persona now when third party cookies are disabled. This was a huge problem before when I was playing around with it a few months ago (it would flat-out never properly authenticate when I was testing it before). Didn't think the new cookie policy would roll out of testing so quickly.
- haddr 13y agoJust one privacy question: Imagine If I log in using the same email to Service1 and post some comment. And later, using the same identity I log in to Service2 to post some pictures. Does Service1 and Service2 (imagine the share some data) know that it was the same person? PS. Good work, it looks quite convincing!
- SteveArmstrong 13y agoThey both know it was the validated owner of user@example.org, so if Service1 and Service2 compare their users, they will see the same e-mail address.
- bluehex 13y agoI clicked on the first link, in the announcement of one of their adopters "The Eclipse Foundation" (actually their Orion project: https://orionhub.org/ https://orionhub.org/), to see what the sign in flow was like. I already had a Persona account from the early announcements but wanted to see it on a real site. The experience was bad. I signed in with Persona on Orion to be greeted with "There is no Orion account associated with your Persona email. Please register or contact your system administrator for assistance." Isn't the whole point that I don't need to register? I clicked the register button to see what more it would require and they wanted a user name, password, and email. With such a poor integration the whole idea of not having to remember another, username and password is lost isn't it? Obviously this particular failure is the fault of the integrating site and not Persona which seems really cool. Screen shot after logging in with Persona; then after clicking register: http://imgur.com/a/WCKnh http://imgur.com/a/WCKnh
- callahad 13y agoThanks for beinging that up. The specific implementation at OrionHub is Not Ideal -- they should kickstart account creation when you sign in with Persona, like at https://voo.st https://voo.st or http://sloblog.io http://sloblog.io I'll reach out to the folks over there and see if that can get that fixed in their next release.
- Ygg2 13y agoAny plans to build this into Firefox? I could definetely see this as some kind of account to sync our Firefox, better browser integration. IIRC Firefox had a plan for BrowserID something along these lines.
- callahad 13y agoYep! The Persona implementation of BrowserID is already built into FirefoxOS. It should come to Desktop Firefox later this year.
- sixbrx 13y agoThe login on the Persona site (https://login.persona.org/signin https://login.persona.org/signin) doesn't seem to work for me, using my Yahoo account. It pops up the Window, I login to Yahoo, that little window goes away, then ... nothing else happens. If I click "verify" again, the little window pops up momentarily and then just goes away. Is it supposed to actually do something, or was that the whole demonstration?
- callahad 13y agoI've filed a new bug for this: https://github.com/mozilla/browserid/issues/3225 https://github.com/mozilla/browserid/issues/3225 Could you please chime in with your browser, version and OS over there?