Introducing Mozilla Firefox Accounts
blog.mozilla.org
blog.mozilla.org
https://wiki.mozilla.org/Identity/Firefox_Accounts
https://groups.google.com/d/msg/mozilla.mozillians/pv5VN2dNY...
tl;dr: it's coming, and this is an important engineering milestone on that path. I'm sure Lloyd and callahad will be chiming in with more details.
(Source: Mozilla employee, not on the Identity team)
I wanna love Mozilla (even bought a Firefox OS phone!) but this is pretty low-level.
Also, this is a new occurrence of scrypt used in the wild.
Nevertheless, I'm hopeful that we'll integrate Persona into the Firefox Accounts workflow, but that's still only part of the problem that Firefox Accounts is trying to solve. :)
(Why wasn't it there at first? We were still working out protocol / data format details, and sticking with a known username/password system reduced the number of variables while reinventing Sync.)
Firefox Accounts, in addition to Persona, could actually move the needle. If Mozilla would drop the idea that email providers should be IdP and instead step into the role themselves (like they kinda are with Accounts) this could all work.
More simply put why not do Persona as an SSO solution independent of email providers (Mozilla or a partner is the single IdP). Optionally attach data to that identity (several technical ways to do this) to hold more data such as that envisioned by Firefox Accounts (email, TOS acceptance, ...).
"Today, we’re introducing Firefox Accounts as a safe and easy way for you to create an account. With Firefox Account can integrate services, like Firefox Sync.
Firefox Sync enables syncing of passwords, bookmarks, history, and open tabs across devices, now even easier to setup the service and add multiple devices"
Hey Mozilla, you are too honest about the cloud thing. :)
Edits: YES! https://github.com/mozilla/fxa-auth-server
FYI, I showed three different designs in that presentation, to compare/contrast 1: original J-PAKE, 2: intermediate not-used SRP thing, 3: final non-SRP "onepw" design. More than one audience member was left confused about which one we're using for Sync. Tell your friends: we're deploying the last one, nicknamed "onepw", from page 20 of that slide deck:
http://people.mozilla.org/~bwarner/warner-rwc2014/#/20
cheers, -Brian (member of Mozilla FxA/Sync team)
And I hope they will implement it on Firefox OS very soon, otherwise the whole syncing is not really that interesting.
[0]: https://github.com/mozilla/fxa-auth-server
[1]: https://blog.mozilla.org/services/2014/02/07/a-better-firefo...
Is that something Mozilla is officially endorsing or something that might perhaps work, good luck with that?
The team is looking to have a more understandable self deployment strategy by the time this ships in Firefox release ~12 weeks. This is not a promise though. Engineering work is tricky to estimate.
I think that the resources put toward this endeavor could have been better spent on improving the performance of Firefox, or perhaps reducing its memory usage, or even fixing the numerous bugs that affect it. Firefox isn't as bad as it once was with respect to those things, but there's still much room for improvement.
Functionality that's useful to a comparatively small number of users should be prioritized well behind core functionality that affects basically all Firefox users.
users expect their browser preferences, history, bookmarks, and passwords to be synced across devices. for a significant chunk of ff users, this is in no sense "unnecessary peripheral functionality"
Trust is such a poor and overloaded word. What is Mozilla "trusted" to do? That's a very difficult question to answer.
Perhaps thinking in terms of expectations would be better: My expectation is that Mozilla will produce a decent browser, with occasional bumps and steps backwards in response to some flavour du jour, most notably in the area of wouldn't it be cools that break usability. Not to mention the mobile browser considering my tablet and phone to be the "same type of device", when my tablet is much closer to my computer - and it's the computer's UX I want everywhere, not the phone's.
My expectation is that Mozilla will produce a half-decent email client that I have no real reason to use.
My expectation is that in doing these things Mozilla software will mostly stay out of my way, mostly work as I expect (sync the function works pretty much as expected, sync the UX is awful - I still need all manner of extension and app to get the "move easily from one device to another" experience I really want).
My expectation is that Mozilla will occasionally cook up something new, e.g., Persona, that I really don't see a need for, and that Mozilla will be unable to articulate why that new thing is needed, cool, or anything else.
If Mozilla disappeared tomorrow, I would be quite upset, because FF sucks far less than every other browser - maybe that's because I am so used to it, that I've made it work for me, but moving to anything else would be painful. My expectation is that they will continue to deliver excellent B+ software that is adequate to my needs and wants.
But why on earth would I expect that I could trust Mozilla with anything more than my sync information?
I trust Mozilla about as much as I trust my bank, as much as I trust Google, and, to be fair, more than I trust facebook. But again, trust is the wrong word: I expect Google to mine my information, make the occasional misstep, but to by and large attempt to keep my information safe and secure, because if they don't, it ain't just mine they release, it's millions of ours, and they cannot afford that.
I expect my bank to mess up UX occasionally, but to do security reasonably well, and to not share my personal overmuch, because of the regulatory framework in Canada: They just cannot mess this up without serious consequence.
I expect facebook to mine, share, intrude, mess around, and generally do stupid things. I am never disappointed.
What should I expect of Mozilla Accounts?
Nothing. Nothing at all, because "Accounts" is so not what I think of when I think "Mozilla". I hear "Mozilla" I think "FireFox", I think half-decent browser, better than others, adequate email client, neither better nor worse, I think confusing cross-device UX...
...but do I think trust?
Nope.
And the "occasional bump in response to something shiny" mentioned above means I never will - at least not without major public rebranding.
If I am going to trust you, you need to convince me you are rock-steady reliable, and never prone to blowing with the wind.
I agree with many of your points because they are in fact excellent arguments. Trust can mean various of things. But in this context, trusting Mozilla is merely trusting Mozilla based on its reputation. Mozilla does not log your password and does not sell you to an advertizing agency so your new shiny Fx Account is really to be used for Mozilla service. At least as far as we know at this point. Mozilla was named #1 most trusted organization [1] but that doesn't mean we should say Mozilla is more trustworthy than Google without considering the context in which the trust is placed in.
The first thing I want to echo is expectation. We expect so and so to do such job and deliver such promises. We expect that when we first sign up the password I pass to Firefox Account and Google Account, my password is hashed and salted with strong hashing algorithm. We expect Mozilla engineers and Google engineers to be honest and professional, so they won't be use MD5 or SHA1 to keep our passwords. But are they? We have to put a bet on Mozilla.
Almost all the Mozilla projects are open-source, meaning they exist somewhere on mozilla-central or on Github. But we can't verify that a server is actually running the code the service provider claims to be using. How can I trust them? I can't. I challenge anyone out there to propose a way to verify server, the same goal we want to have for deterministic build.
Unlike some startup which claim to be secured, Mozilla does not brag about security without hard work. They don't come up with their own new crypto and ask the community to challenge them. They are careful about code changes. With that, we say Mozilla is trusted. Google is therefore also trusted.
There are two kinds of trust:
First, people with first-hand access. They have access to some part, if not, all parts of the infrastructure. If you are running your own Persona identity bridge [2], you can verify yourself that the password you enter is hashed and salted with strong hashing algorithm and iteration. This is a great news for people who are paranoid about a particular website not handling your password properly -- provided that Mozilla sends your data over TLS channel and does not log your encrypted password in the middle.
Second type is based on experience, based on reputation. Google and Facebook employed thousands of engineers. If either is evil, then we would have heard a whistleblower gone on public already. Because there is none (or little) we expect them executing my expectation: my password is hashed and handled properly. So I am happy to stay as a Gmail user and authenticate my Gmail as Persona account. I know both Mozilla and Google will do the communication properly.
I am not an expert in either privacy or security, but I feel like people forget about the mission of the organization. Is Google bad? Is Google evil? The #1 argument is Google is for-profit and Mozilla is non-profit (yes, there is a business entity called Mozilla Corp which exists to handle business contracts like search engine option in Firefox), so Mozilla is more trustworthy, right? Since Mozilla is non-profit and it doesn't talk to advertiser or does not customized your search experience, there is little to no incentive for Mozilla to sell your data and have an advertising agency to customize your experience. With that, Mozilla's reputation is not touched.
Mozilla doesn't about your search query or activity EXCEPT metrics. How many users are experiencing such and such crash? Who is adopting such option and such. How many web servers are still negotiating RC4 cipher? Is Firefox stable? Is people happy with the security and privacy controls?
They don't care if you are bidding a cat on the Internet or voting Doge to be the next President of United States. The expectation of Mozilla is to make good things. For example, Mozilla Firefox should provide Do-Not-Track and private browsing (e.g. search record is not logged in the user's browser history). And Firefox does it. Unfortunately, there are issues but Mozilla are committed to resolve them in the best manner as possible. For example, should the default option for DNT be "tells site I don't want to be tracked" or "don't tell site about my DNT preference?" Currently the latter is the default option. Good or bad? One hand Fx is used by all sorts of users and many sees DNT and DT makes no difference and they might prefer to be tracked. This is why metric is important to a browser vendor like Mozilla. If 90% of the users are aware of DNT, if 90% are adopting DNT and "Tell sites I do not want to be tracked" is high and more and more sites are honoring DNT header, then the default would of course be "tell site DNT." [3] Are there information Mozilla should not be collecting? Probably. And you should challenge Mozilla if you are concerned. While not all Mozillians are created equally - they don't all think alike or agree on everything, one voice can have a snowball effect.
So in terms of interests, Mozilla has a much lower interests in anything else but the number of users able to use Firefox and its related services. After all, Mozilla wants to be the browser that everyone can trust and use. But it doesn't mean Mozilla can override everyone. Some of the proposal Mozilla makes are excellent but often rejected because other vendors proposed something else. Mozilla will have to decide how to resolve such challenge.
So why should you or me trust Mozilla alone?
Mozilla is an open-source organization and therefore almost everything they do is publicly listed. Many project meetings are open and publicly documented (but of course there are exceptions -- sometimes people don't remember they can make such meeting public, or because it's security/corporation/business confidential). But eventually, Mozilla releases notice about decisions they are making. This is not something Google or Facebook is likely going to do. But that's fine. Google and Facebook are much much larger than Mozilla and are entirely for-profit. Take Chrome vs Firefox. Yes, not Chromium. Chrome is closed-source, building upon Chromium. There is no closed-source Firefox releases by Mozilla. Since Firefox code can be viewed publicly, anyone can audited the code. I believe gps is working on deterministic build [4]. Since Fx Account is also publicly readable on Github and mozilla-central, the security of Fx account is both theoretically and practically more trustworthy than Chrome's Google Account implementation (though I believe Chromium users can connect to Google services the same way Google Chrome allows) -- provided that you put a bet on Mozilla's ability to take care of the infrastructure and is actually hosting the version it claims to use. If Persona is ever integrated into Fx Account, then it would be much nicer than Google Account in Chrome, since one can authenticate against one's own identity provider, not Google's or Mozilla's.
Furthermore, it is amazing to see how much Mozilla is capable of doing. It doesn't have 30k employees but Mozilla is capable of keeping data safe. I haven't really heard of Mozilla compromised (community servers, yes) yet. Somehow, this is strange to me. I might be too young to remember such incident, but in the recent years, officially? I haven't heard of one. So people at Mozilla are running a nice farm. I can trust the skill these people have.
Lastly, I do agree that UX is important. Google, Facebook and LinkedIn all have some awful UX to control security and privacy. Some features are not opt-out-able easily; some require deleting an account or disabling access to other core products. I urge everyone, including myself, to make the ability to control security and privacy settings as easily as possible. I think such improvement can make any organization more trustworthy - after all, if I can't opt in/out easily, I am locked in with default settings.
With that, I say I can trust Mozilla. I can trust Google, I can trust Facebook. I can trust many websites out there. But if there is an option and if time allowed, I'd work hard to harden my own identity. With that, I think Mozilla is trustworthy. If we continue to make control of privacy and security a priority over complex feature, some people will trust XYZ more.
[1]: https://blog.mozilla.org/blog/2013/01/28/privacy-day-2013/
[2]: http://identity.mozilla.com/post/46374271364/persona-is-dist...
I understand Mozilla is in a tight place with no access to iOS, little market share in mobile in general and the new walled gardens erected by Google, Apple, FB and soon Microsoft. But simply playing copy cat and catchup does not cut it.
Only a couple of months ago comments like mine would have been passed off as tin-foil conspiracy. Now, I think everyone's sense of normal is now tightly wrapped in tin-foil, encased in lead.
http://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/lates...
Same with all the English (US) versions in fact. Other languages appear to work.
Only thing I didn't love was the icon, but its beta so hey.
Link to Aurora nightly:
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/latest-mozilla-aurora/
I mean, it was definitely too many steps, and it wasn't labelled clearly enough which device was the master and which was the slave, but those are more like "users won't bother to find it" troubles, rather than it actually being difficult if you want to turn it on.
https://news.ycombinator.com/item?id=7200425
Basically, many assumed it was a backup program. Recovery was painful. There was multiple iterations of enhancement before they decided to roll out Fx Account, it was clear that users didn't like the original Sync.
Fx Account is more than Sync. This is like having a Google account and allows you to connect to Mozilla services like Marketplace and all instances of Firefox a user owns.
Easy can still be frustrating (as in why all these steps and which machine is which, and why do I even need to look up how to do this?), and it can still be user unfriendly (as in not allowing recovery).
I'm hoping with this it will turn into something close to Chrome's sync
Bummer. I've been waiting for more than ten years to get a firefox email account.
What's the easiest way to have hundreds of millions of loyal followers that use your web services on a daily basis?
Email.
That's the starting point, besides the browser.
I've got more pressing matters than yet another account with personal information and data kept in the US ...
See the corporation's audited financial statements:
https://static.mozilla.com/moco/en-US/pdf/Mozilla_Audited_Fi...