17 ms·
It's easy to casually dismiss Persona's lack of adoption but there is real problems with it. For example it is not easy for hosting providers to deploy (custom
by urptght 12y ago
It's easy to casually dismiss Persona's lack of adoption but there is real problems with it. For example it is not easy for hosting providers to deploy (custom domains, domain:443 may not be controlled by the provider, SSL certs, etc).
- callahad 12y agoI'd love to take another run at Persona in a few years once DNSSEC gets sorted out. As the world exists today, requiring a specific response to GET /.well-known/browserid over TLS on the apex seemed like the most reasonable option.
- urptght 12y agoACME and LetsEncrypt should allow for easy to deploy and free (or cheap) certificates this year. With that and the use of SRV records to find the HTTPS endpoint, it could well be made simpler to deploy Persona this year. (For those unfamiliar with SRV records, they're found at _service._proto.domain and contain a target name and port at which a service for domain can be found. ie: _persona-https._tcp.user.example could list provider.example:8443, and provider.example:8443 would be expected to be able to produce a certificate for user.example.)