Identity/Persona Shutdown Guidelines for Reliers
wiki.mozilla.org
wiki.mozilla.org
But this is a lot different than Persona, right? Portier is passwordless login via email (with special handling for Gmail), whereas Persona is another of those "Log in via" buttons (simply speaking)?
Portier is passwordless login via email, with optional special handling right now only for Gmail, yes.
1. Click "Login with Portier" 2. Enter email 3. Click on link in email 4. Be logged in
?
However, ideally you would not "Login with Portier", you would simply "Login". There is no need to mention the infrastructure used (and in our current modules, we simply generate a plain Login-Form without any branding).
You also do not have to click on the link, you can enter the code which is in the email. Useful when mixing clients.
And finally, when using a email provider with special support (currently: Gmail) you don't click on the email and also don't get one. You just login via Google-Sign-In and get then redirected to the site you are trying to login to. I hope we can support more providers (and custom domains soon). Not having to go into the emails is pretty nice.
Edit: Also see https://github.com/portier/portier.github.io/blob/master/Des... for a more technical view on what happens here.
There's also less emphasis on branding; as a user you will rarely see Portier mentioned.
...the account story in Persona was way more complicated than it should have been, mainly stemming from the notion that per-login email confirmation loops were too onerous to be viable, and from the idea that users wouldn't succeed with Persona unless it remembered and displayed all of their email addresses in a consistent, persisted account chooser.
We certainly currently intent to.
That said, I'd love to ask what you found compelling about Persona's promise of browser integration. The privacy aspects? User experience? The finality of a standard successor to HTTP Basic / Digest authentication? Something else entirely?
I think this is one of a few areas where a browser or extension developer can create something that will force every other browser vendor to adapt, sooner or later.
Last time I feel that happened was with tabs, so IMO this should is a high-value target even if nobody seems to be interested ATM.
A decentralized way to authenticate users securely and privately would be an exceptional addition to the open internet.
Unfortunately in this case the financial incentive and favors those building "information silos" where the purpose is information collection for profit.
I wonder if SMTP would ever see the light of the day with the current mindset as opposed to a "Facebook Messenger"-like multitude of services, much like what happened with the IM fragmentation.
Hosting a service at the level of security and availability required for an authentication system is no small undertaking, and Mozilla can no longer justify dedicating limited resources to this project. We will do everything we can to shut it down in a graceful and responsible manner."
I find this a bit confusing because citing low usage and lack of growth is something I'd expect to hear from a for-profit corporation, not a well funded non-profit. Have they shared information on how expensive it is to maintain Persona? I'm also unaware of any pledge drives to get funding for it.
This is a self fulling prophecy
I'll be presenting a keynote on this topic at linux.conf.au in January, which should hopefully add some nuance around it.
(article author here)
To add to @callahad's excellent points: unmaintained critical infrastructure on your security perimeter is even worse, and a service like Persona is about as security-critical as you can get!
Persona was (and will remain until the end of November) covered by Mozilla's bug bounty program, meaning that it has been getting regular security bugs filed against it. Most have been spurious, some have not, but each of them has been a fire-drill because Persona gates access to so many of Mozilla's internal services.
We have been able to respond effectively so far, because there's a core of ex-Persona developers kicking around other projects at Mozilla, who we've been able to pull back in for these critical maintenance tasks. But that's not sustainable indefinitely.
The only responsible choices for a security-sensitive service like this are (a) staff it properly, or (b) tear it down gracefully. I'm personally quite disappointed that we couldn't find a path to success for Persona at Mozilla, but I'm grateful we've at least found the resources to do (b).
So now we must rely on Google, Facebook or other mega corporation for identity services and let them hold our critical, private personal information that they can exploit for commercial and other unknown ways.
Mozilla seems to wonder why people don't seem to understand its mission and purpose any more. Perhaps that's because - despite what it's achieved in the past - as an organisation they no longer seem to want to tackle truly important but difficult issues like identity management.
I still think there's potential for improving user authentication in a way that's usable, privacy conscious and fast, without a costly shim service like persona.org. Maybe Firefox could finally implement the Persona API in the browser for sites to use?
Can someone tell, in a nutshell, what the difference was between OpenID/OAuth (I mean whatever the heck it is that allows me to "log in using my Google/Facebook/GitHub account". I always mix up those two.)?
Is it just that you use your e.g. Gmail or other third party email address, but then the authentication is not done by your email account provider, but by Mozilla?
╔════════════════════════════════════════╦═══════════════════════════════════════════╦══════════════════════════════════════════╦════════════════════════════╗
║ ║ Persona with browser and email server ║ persona.org shim ║ OpenID ║
║ ║ integration ║ ║ ║
╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣
║ User identifier ║ email address ║ email address ║ URI ║
╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣
║ Auth provider ║ Email server ║ persona.org ║ OpenID server ║
╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣
║ Passwordless ║ Just one password for your email server ║ One for the shim, and one for your email ║ One for your OpenID server ║
╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣
║ Provider sees where you log in ║ No ║ No ║ Yes ║
╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣
║ Provider must stay online at all times ║ No, auth tokens are cached ║ No, but persona.org must stay online ║ Yes ║
╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣
║ Requires Javascript ║ Yes ║ Yes ║ unknown ║
╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣
║ Fallback available ║ Yes, just use the email ║ Yes, just use the email ║ None ║
╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣
║ Ability to contact user ║ Yes, just use the email ║ Yes, just use the email ║ None ║
╠════════════════════════════════════════╬═══════════════════════════════════════════╬══════════════════════════════════════════╬════════════════════════════╣
║ Implemented ║ In no desktop browsers or email providers ║ Yes ║ Yes ║
╚════════════════════════════════════════╩═══════════════════════════════════════════╩══════════════════════════════════════════╩════════════════════════════╝Provider must stay online at all times: the OpenID provider needs to be online when you login to the consumer site, after that, you have a session with that site and the provider doesn't need to be online.
Requires Javascript: there's a fallback in OpenID.
Ability to contact owner: there are extensions to propagate attributes like email addresses that are commonly supported.
Whereas by design, Persona does mean the service provider has access to your email address. For consumer applications, this is probably fine, but it's a very different assumption than most access and authorization use.
I can't parse this headline. It sounds like a weird psychological problem of some sort ;-)
Non-English word anyway.
The project failed to gain widespread adoption. An org that runs marginally valuable side projects indefinitely is an org that is going to face a downfall.
Like you, I'd love to see a better authn mechanism, but Persona wasn't going to be it. So, this frees their resources to focus on what is going to continue making Mozilla relevant. Certainly a declining user base on Persona wasn't going to be it.
It kinda feels like they gave up before they really got started.