Any plans to pin the login.persona.org SSL certificate in browsers? It seems like a pretty tasty MITM attack target, especially while most identity providers don't have native persona support.
login.persona.org is listed in the key pinning list in Chrome[1], but marked as kNoPins, DOMAIN_NOT_PINNED - whatever that means.
[1] http://src.chromium.org/viewvc/chrome/trunk/src/net/http/tra...