4 ms·
Persona solved a real problem in a straight-forward manner, which, in today's web, is a surefire way to fail. People often complain about things (Facebook being
by hmans 12y ago
Persona solved a real problem in a straight-forward manner, which, in today's web, is a surefire way to fail. People often complain about things (Facebook being a walled garden, Twitter mucking up third party clients, authentication being broken etc.), but then end up giving in to convenience.
- deleted 12y ago[deleted]
- urptght 12y agoIt's easy to casually dismiss Persona's lack of adoption but there is real problems with it. For example it is not easy for hosting providers to deploy (custom domains, domain:443 may not be controlled by the provider, SSL certs, etc).
- callahad 12y agoI'd love to take another run at Persona in a few years once DNSSEC gets sorted out. As the world exists today, requiring a specific response to GET /.well-known/browserid over TLS on the apex seemed like the most reasonable option.
- urptght 12y agoACME and LetsEncrypt should allow for easy to deploy and free (or cheap) certificates this year. With that and the use of SRV records to find the HTTPS endpoint, it could well be made simpler to deploy Persona this year. (For those unfamiliar with SRV records, they're found at _service._proto.domain and contain a target name and port at which a service for domain can be found. ie: _persona-https._tcp.user.example could list provider.example:8443, and provider.example:8443 would be expected to be able to produce a certificate for user.example.)