It's up to the users to trust the domain he is going to use as identity. Just like many people trust Facebook Connect.
It's up to the users to trust the domain he is going to use as identity. Just like many people trust Facebook Connect.
Why should, for example, google, ever trust, say, fred's discount web hosting, enough to let them login to gmail?
Not in the sense of "these guys could compromise gmail" (which is a worry in certain elevated privileges contexts), but more in the sense that "people are still going to say 'my gmail got hacked'" if their gmail gets hacked because they made bad choices. They do now!
Google will still get blamed, and their only real option is to decide not to accept certain identity providers (IE blacklist or whitelist). Long term, how are we not going to end up with just a mishmash of who accepts what?
I've read a bunch of docs on persona, and it doesn't seem to address this past stating how wonderful user choice is, and how making this more distributed will make the web more secure (which seems, well, wrong)
If your email provider is vulnerable, you're already fucked, except for those accounts which use two-factor auth. And persona isn't intended for your bank/etc.
Now we are fucked, after we're just as fucked but not using facebook as the identity provider?
I guess i don't see this as much of an improvement? Honestly, i'm not trying to be snarky. I'm just trying to understand why this seems to be presented as leaps and bounds above what we have now when it seems to be just as bad, just more distributed :)
It's an improvement on having dozens of accounts on dozens of sites, both from a security standpoint and a UX one.
They're not. They're letting users who use Fred's discount web hosting as their authenticator to log in. Fred's discount web hosting won't even know when their users try to log in to gmail.
Letting someone authenticate that way is no different than allowing passwords than many users reuse all over the net, including on dodgy sites that might very well take that gmail address and password they were handed and see if they can log in to the gmail account with it (want to be on how many users use the same password on their e-mail and other sites they sign up to _using_ that e-mail?), or writing it down all over the place.
> Long term, how are we not going to end up with just a mishmash of who accepts what?
If we do, we're no worse off than we are today.
I'll take that as inspiration for a future blog post. Thanks for pushing us, please continue to do so. We listen.