6 ms·
I'm sorry, I might just be misunderstanding so please correct me if I'm wrong but... The main vulnerability he talks about is if a major provider were to be ha
by fournm 13y ago
I'm sorry, I might just be misunderstanding so please correct me if I'm wrong but...
The main vulnerability he talks about is if a major provider were to be hacked and have their file replaced (or go rogue, entirely). In either case, is any login system that doesn't use two factor authentication and allows for password resets via email really going to do any better?
Edit: I realize he points out that 2 factor auth really is the only solution here, just, it seems like the criticism applies much more widely than just against Persona.
- callahad 13y agoIt's more than just 2-factor, your site has to control the second factor. E.g., even if you're using Google OAuth and requiring folks to have 2FA turned on, Google still effectively controls both of the factors.
- drdaeman 13y agoThe main problem with Persona (and OpenID and OAuth) is that you don't own your identity, by design. The identity is completely managed by provider, so anything that uses Persona is inherently prone to all sorts of identity provider abuse. Analogy: you don't have any keys to your safe deposit box at bank, but a warden may open it for you after a phone call to your landlord, who'd assert your identity. The obvious question is why we need a landlord in this scenario. Unfortunately, gpgAuth is practically dead and WebID WG had no progress for two years.
- callahad 13y agoIt's a delicate balance between security and usability. Zooko's triangle applies here. To wit, GPG and client-side SSL certificates have pretty ideal security properties, but impose upon the user to manage storing and syncing key material between devices. http://en.wikipedia.org/wiki/Zooko%27s_triangle http://en.wikipedia.org/wiki/Zooko%27s_triangle EDIT: Heh. Actually Zooko's doesn't fully apply here, but it's still a fun read. Thanks Perseids and drdaeman. :)
- Perseids 13y agoZooko's triangle is about secure name systems like DNSSec or Namecoin, not about user logins.
- dllthomas 13y agoAccording to the wiki page, it's "a conjecture for any system for giving names to participants in a network protocol". "Nicknames users choose for themselves" is listed as one example point in the space.
- drdaeman 13y agoFrom what I've seen Persona is mostly advertised as solving problem with credentials (passwords, OpenIDs, etc.), not nicknames. Actually, I don't think there's anything wrong with nicknames and their lack of global uniqueness. Moreover, I believe it's a good thing.
- dllthomas 13y agoPersona solves the problem of uniquely naming you to the site, on the assumption that you already have a unique email. There's more pieces here with their own issues, but I think Zooko's triangle is still relevant. "Actually, I don't think there's anything wrong with nicknames and their lack of global uniqueness. Moreover, I believe it's a good thing." That depends entirely on the applications you're intending to put them to...
- drdaeman 13y ago> the problem of uniquely naming you to the site Ahem. Did we (consumers, not site owners) really have this problem, to begin with?
- dllthomas 13y agoThat's irrelevant to whether Zooko's triangle applies, which was all I was weighing in on. That said, yes, consumers totally have this problem. We encounter it visibly every time a username we want is taken when we try to sign up for a site. The effectiveness with which Personal eliminates it entirely, ameliorates it, or merely pushes it off to other parts of the system depends on other details of the service in question. It's also not the only problem Persona purports to solve, simply the relevant one.
- Steuard 13y agoIf I understand Persona correctly, you are entirely welcome to have the bank keep your cell phone number on file instead of your landlord's number. You only need to rely on a landlord if you don't want to go to the trouble of carrying a phone of your own.
- drdaeman 13y agoIf you meant I can setup my own Persona auth server on my "own" domain, then it's just that my landlord is my domain registrar. It's probably less likely that one would be stripped off "their" domain name than of "their" email account, but the problem still remains. The fundamental principles don't change in this scenario - none of credentials are in your direct possession. If you meant that Persona consumer site can consider Persona to be not an identity but a credential, and ask me for a secondary one (2FA), then you're right. But the question on why need a landlord as a part of authentication protocol remains open.
- Steuard 13y agoAh, I see your point now: my cell phone carrier can still trick the bank into unlocking my safe deposit box. But can't we do something similar for every possible system? By controlling my computer's OS, Apple could in principle have a copy of my GPG keys and passwords right now. Ok, I'll use Linux... but do I need to worry about Intel recording the same data somehow? The point is, I'm constantly being forced to store my credentials in someone else's hands.
- drdaeman 13y agoWell, not really. You could build your own HSM, that would store your keys and sign things for you. Obviously, only with your physical permission (a button press or even a PIN entry). An AVR (like Arduino) would suffice without much need to trust hardware vendor. It has no communication channels except for the one you define (and you can and should define quite a restricted one) and not much die space (and too low cost) to have a backdoor to begin with. (And really paranoid ones could always go with TTL.) The only serious problems are cryptographer-vetted RSA implementation that would fit in an AVR and writing a PKCS#11 driver for such HSM. Yeah, this is totally on tinfoil-hat-grade paranoid side of things, but a CPU-level backdoors are not far from that.
- maxerickson 13y agoPeople don't want to understand or care about identity and authentication. In that context, a nice thing about persona is that it makes things easier without really introducing any new problems (email is already a control point). (I'm tempted to say people don't care, but I agree that they mostly don't want other people accessing their accounts)
- drdaeman 13y agoMost don't. Some do. For those who don't it shouldn't matter whatever they're using (some third party account or a personal certificate or a saved password) to authenticate. They click "login" and they get what they want. For a minority of those who do, leasing their identity from a third party probably don't looks like a good idea.
- maxerickson 13y agoSure, but if the question is between medium value sites leaning on sending emails to control accounts and medium value sites leaning on persona for identity assertions, there aren't really any new issues, and all those people get rid of some passwords. It doesn't solve your problems, but it doesn't make them significantly worse and it is a step forward for most people. (I actually think the use of an email address in persona is genius, anybody who wanted valid email addresses would never consume something like OpenID)
- dochtman 13y agoOn the other hand, those people can mostly run their own IdP, so they depend on fewer/more trustable parties (just the DNS registrar, and their colo?), but still get the same user experience. Which I think is an important property: if you can come up with a better or more secure IdP experience, you can enter the ecosystem without the ecosystem (that is, Relying Parties) having to change anything. That's a huge win over the current state of login.
- yeukhon 13y agoThe main problem with Persona (and OpenID and OAuth) is that you don't own your identity, by design All three work alike if you run your own IdP. If you are yourself OAuth provider then you can control your own identity. If you don't trust Mozilla being your IdP (which you probably shouldn't if you are paranoid), you run your own IdP. Am I wrong?
- drdaeman 13y agoYou can't really own an IdP as you can't truly own a domain name, by which IdPs are identified in OpenID/OAuth/Persona protocols. With your own server you'll have to lease your identity from the domain registrar. In contrast, with certificate-based credentials you actually possess the keypair.
- _wmd 13y agoA slightly less overloaded summary might be "users must trust their identity provider", which is true of every authentication scheme I'm aware of except for perhaps PGP, which itself is a usability nightmare for 99% of the planet No clue what point this post was trying to make
- wtbob 13y ago> A slightly less overloaded summary might be "users must trust their identity provider" And every CA in the world. And trust that the identity provider is always competent (i.e., that the .well-known/browserid file is never compromised). Which isn't really true of usernames & passwords--at least that way a mistake at my mail provider doesn't automatically expose my banking account to risk.
- yeukhon 13y ago> which is true of every authentication scheme I'm aware of except for perhaps PGP I am not getting your point about PGP. Using PGP as Identity authentication? Wouldn't it just be the same as running your own IdP?