Persona fails to solve a problem which either end-users or people who operate websites for profit actually have.
Persona fails to solve a problem which either end-users or people who operate websites for profit actually have.
Why aren't people using it even in that sphere? One issue is that it's precisely when you need to take advantage of the federated aspect that the win on up-front effort is weakened. By the time you're setting up your own in-house Persona server rather than using Mozilla's, you're probably at the point where it's less effort to just use some crappy off-the-shelf account-management system that comes as a CMS plugin. This might be counteracted if using Persona improved conversion, but that's a chicken-and-egg problem as long as users don't recognize Persona.
The other bit imo is that the security downsides of roll-your-own are a bit of an unpriced externality. If you have a password breach, it's bad PR for a bit, but legal liability around it is relatively toothless: data-protection laws seem not to care about mere incompetence in keeping users' data private. Make your users pick passwords with at least 2 digits and 2 non-digit characters and you've "done your part". So rolling your own crappy login system doesn't have as big a downside for you the provider as for your users. The users, for their part, are oblivious to the risk before the fact, and lack serious legal recourse after the fact, so they'll go along with your crappy in-house signup system, and shoulder the risk.
Developers/tech savvy people have hundreds of passwords for all their services. The serious ones use Keepass or similar to store the passwords, and don't have a problem.
The "normal" computer user does not have hundreds of passwords. They have a few. And they give them all the same password, or similar enough. They don't have a problem remembering them, because they're simple, easy-to-remember passwords (e.g. that can be cracked).
Is this a good situation? No. But people don't know it. And implementing a whole new system to solve a problem that most people don't know about is simply not going to help.
I disagree. The end user benefits from being able to quickly sign up to a service without having to validate his/her email address.
The developers benefit from not having to store passwords.
A. Not everyone has an FB account. B. Those that do don't always trust that logging in with FB won't mean that the website they're logging in to will spam their wall.
So how does it solve a problem these sites actually have? Some small percentage of end users have this problem (the ones demanding a solution to privacy problems), but the rest don't think it's a problem, apparently.
(Surveys up the wazoo that show that people care about whatever mean nothing when people don't actually change their behavior)
That's not apparent at all. As far as I know, lots of people never even heard of Persona. I thought it was still beta. It's just in the works, so it makes sense not everyone jumped on board. There wasn't tons of marketing even.
That's huge.
[1] http://www.letscodejavascript.com is profitable enough to support me full-time.
Let's not forget that for a vast amount of people, this just means remembering a single username+password.
Even just for login, though: Persona doesn't solve this problem as well as Facebook Connect (from either the perspective of the site administrator or the user) as it assumes email addresses are canonical and unchanging, which is not true for normal users (who tend to change email addresses occasionally to get rid of spam or old contacts they no longer like; they also often get their email addresses only temporarily from schools, employers, and network providers). Please understand: I have had the same email address since the late 90s, and likely most people reading HN care about canonical identifiers, realize the security issues involved with losing their email accounts, and often have business reasons to not lose access to old contacts--we are not "normal people".
With Facebook Connect the user normally cares more about their account (people change Facebook accounts much less often than email addresses), and when their email address changes they can update it on Facebook without bothering the site they are using. (I run a site that uses only external login providers, either Facebook or Google, and the users who log in using Google often contact me saying they changed their email address and now can't log in to my site anymore as they had to make a new Google account. I frankly only offer Google because some people hate the very idea of Facebook.)
This undermines one of the major advantages of using third-party authentication providers. For site administrators, it means you still need some way to identify and authorize accounts separate from Persona (so as to know the user contacting you, who no longer had access to their old email address, is really the user they claim to be), and for the user it means they still have to find all the websites they have previously logged into in order to correct their email address, and they must do so manually and painfully (potentially talking to a customer support representative).
If all Persona did was "email verification" that might actually be kind of awesome, and then have that tied to an existing login system (maybe one involving a username and a password) provided by the site (or even by a third-party), but it ends up being sufficiently intrusive to the flow that it just doesn't feel right to use it and another login mechanism, which means that these killer "email changed, don't have access to old e-mail address" issues become entrenched. That also isn't how Persona was marketing itself, so no one seems to think to use it that way (leading to the "it doesn't seem to better solve a problem I really have" issue).
(I have written more about this subject in the past, with at least a small amount more detail on some of the other problems that can arise with relation to email accounts provided for temporary use, such as by the aforementioned schools, employers, and network providers; the short version, though, is that email addresses often get reassigned, which makes the entire idea of using an email address as the basis of what is supposed to be a widespread secure login mechanism insane. OpenID has tons of its own adoption issues, but at least it required providers to never reuse their identifiers between different people, and provided a simple way to allow that to be possible... I mean, even Yahoo and Hotmail expire and recycle accounts, so this is a serious problem.)
The easy solutions I can come up with to this problem negate all the benefits of Persona past "email verification without sending an email", which is a non-problem for most people, and not how Persona is marketing itself (in particular, you can't rely on it as a login provider: you need a password or something instead). It is ludicrously irritating to have to deal with these issues manually; at least Google (which also causes this problem) offers other benefits (names, genders, profile pictures, and with G+ a list of friends to easily add social features). The other options you have are ludicrous "account recovery" flows, such as Facebook's "get five of your most trusted friends to vouch for you" mechanism, which shouldn't be needed for this all-too-common case.
Persona is better than the other centralized login systems in this respect, and is second only to username/password. Username/password can identify you after you've changed whatever you like, but it's not centralized, so we're comparing apples to oranges.
People delete their Facebook accounts much more rarely than they delete their email accounts. There is simply very little reason to delete your Facebook account other than "I have decided I am afraid of Facebook", a thought a normal user doesn't have (the only people who have this thought are the tiny percentage of highly paranoid people that probably didn't use Facebook to log in to your site in the first place ;P). For whatever reason, normal users delete their e-mail addresses constantly. Normal users also often use third-party provided email addresses (from schools, employers, or network providers), and thereby will lose their email address; that is never true of Facebook/Twitter (though it does happen with Google Apps accounts, which sucks).
This problem ("user lost access to their email address") is thereby orders of magnitude greater in prevalence than "the user deleted their Facebook account"; the latter problem is so rare that "they can send us an email and talk to a customer service person" is reasonable, but for the former problem you really need some kind of automated solution... (as it stands, the fact that I support Google login for Cydia is a serious problem on this front: while users can delete their Gmail accounts without deleting their Google account, and can then link their Google account to a third-party non-Gmail email account, none of them ever do this, and most normal users don't even realize it is possible).
> You aren't just screwed, but there's no way to change login accounts at all, even if you go around to all of your sites beforehand.
You make this problem sound worse than the Persona problem, but it is in fact the exact same problem as Persona: Persona is, for every email account, like a separate Facebook/Google/Twitter account. If the website somehow magically solves this problem for Persona (such as offering "transfer account to another federated login account"), this problem is identically and immediately solved for all these other account mechanisms as well. Persona offers no advantage on this front, and yet has the as-described worse property of being directly tied to the one thing users seem to not value much or even have no control over (their email address), leading to the common "I deleted my account before I transferred it" issue.
> Username/password can identify you after you've changed whatever you like, but it's not centralized, so we're comparing apples to oranges.
The core of this argument doesn't start with a comparison: this is an explanation that Persona fails to solve a key problem (user changes email address) that is sufficiently common that any large low-margin site will need to implement a password-based login system as a supplement (unless they can come up with a reasonable "account recovery" flow, which is hard and almost always a serious security issue), at which point Persona becomes redundant (again: the only problem it is solving is email verification without sending an email, which is a "non-problem" for most people, and not worth the separate branding and the external dependencies). That said, Persona really isn't centralized anyway: it is in fact decentralized federated login, with no "centralization" that can be used to store any account information at all.
Isn't it weird that email for normal people is more ephemeral than social networking accounts? I wonder what the best way of getting that stickiness would be, without relying on these big third party providers per se. Perhaps Persona, but more towards an ID rather than focusing on an email? I need to do more research on this.
I've also had a work email that was deleted (when I changed work), and a college email that was deleted (when I changed college).
There are many email address providers and many people have many email addresses.
Many people have their email address provided by their employer. And many people use this address as their contact address in even non-professional capacities. I presume such people also use their work address to sign up to web sites/services. When they change jobs the old address dies.
The same applies for students in schools or universities and it once applied to the ISP's customers too.
Is the name of the site a secret? How many sites have this many users (I understand you talk about registered users, since we're talking profiles/login issues here)?
It sounds like Persona will move in the right direction of being a really simple way to confirm an email address without other privacy implications. That seems like a great deal to me over having to maintain and de-dupe huge lists of passwords in every device / browser you use.
Firefox hasn't been in a good place lately. Most of the changes since Firefox 4 haven't been to the users' benefit. It's like these changes have been more about imitating Chrome, regardless of whether or not this is good for Firefox's users. Yet Chrome is still superior where it really matters, such as performance and resource usage. If Firefox users are just going to get a Chrome-like experience these days, but not as good as that offered by actual Chrome, then they might as well just move to Chrome. And I think that's exactly what we've seen, and why Firefox' usage numbers are dropping.
We see the same with Firefox Mobile. It really isn't superior to the alternative browsers in any way. In many ways it's significantly inferior. There's really nothing to pull users to it.
Thunderbird was perhaps their second most useful product, after Firefox. Yet they've basically given up on it now. I know I've migrated to another email client, and many others have chosen to do the same, too, now that Thunderbird doesn't really improve over time. Even then, the changes we've seen lately have been more harmful than good. The UI is less usable now than it was in earlier release, for instance.
Firefox OS is another example. It really doesn't offer anything tangible over Android, iOS, or the many other mobile OSes that already exist and already widely available on many devices. In fact, it offers a very limited development environment compared to the alternatives, which surely doesn't help its case. The only reasons I've heard to use it are ideological, about Mozilla somehow being "more open" or something of that sort. That's just not enough to gain real traction, I'm afraid.
And Persona is yet another example. It just doesn't meet the needs of its potential users.
Rust is perhaps the only interesting thing I've seen coming out of Mozilla lately. But it has taken a long time to get to where it is, and I'm not sure if it still has the momentum to have the impact that it might have had were a stable version available a year or two ago. Go, and even C++11, can now provide a lot of its benefits today, if not much earlier.
I think there's been a lot of wheel-spinning at Mozilla lately, in terms of their offerings. Their successful products are being ignored or actively made worse, while their new offerings don't actually benefit a wide audience, or offer an insufficient amount of benefit.
I'm not going to pretend to know how to fix these problems, but focusing on product that users actually want, and giving these users the functionality they want, may be a good start.
It isn't: http://www.tomshardware.com/reviews/chrome-27-firefox-21-ope...
>Firefox' usage numbers are dropping
Numbers have mostly stabilized during last year: http://gs.statcounter.com/
>We see the same with Firefox Mobile. It really isn't superior to the alternative browsers in any way
It's the highest rated browser in the Google Play Store.
That said, I never understood the problem that Persona was trying to solve.
In short: how can we get "sign-in-with-Google" but with anything and not just these big players and protect privacy fully?
because one project doesnt work out... lets conclude all other projects sucks! such a cool argument.
im typing this from "firefox mobile" - its called firefox or fennec however. it has a high rating on the play store.a 4.5 stars. it works very well too, much better than chrome has for a long time.
The main benefits of Rust are (a) bare metal performance with zero overhead with (b) memory safety, for security and developer happiness. Go lacks (a), with its mandatory runtime, garbage collection, and ecosystem based around a non-optimizing compiler, and C++ lacks (b), with its memory safety problems that are real, pervasive, and cannot be fixed without breaking backwards compatibility. What you said is only true if by "a lot of Rust's benefits" you mean "basically none of its benefits".
It sounds like you are unhappy with some of the user interface decisions in Firefox and are trying to use this story as a way to spin this out into some sort of narrative of Mozilla's decline and stagnation.
Since I can get perhaps 90% of the benefits of Rust today using other languages that I can actually use seriously, I might as well just use them. Had Rust been more stable in 2012, maybe it'd be a different situation today.
And you can read my original comment again, if the big picture isn't clear to you. I hope it's obvious then that this is far more than just a few bad UI decisions involving Firefox. That is an issue, of course, don't get me wrong, but it clearly goes much beyond that.
Almost all of Mozilla's major projects, from Firefox, to Thunderbird, to Firefox for Mobile, to Persona, to Firefox OS, and even Rust are suffering from some pretty serious detachment from the needs of their users. This is resulting in a decrease in adoption, like in the cases of Firefox and Thunderbird, limited adoption in the case of Firefox for Mobile, or basically no adoption in the cases of Firefox OS, Persona and Rust.
> Since I can get perhaps 90% of the benefits of Rust
> today using other languages
Incorrect, unless you're one of the rare few using Ada or Cyclone. Bare-metal memory safety is fundamentally impossible in both Go and C++. > Had Rust been more stable in 2012, maybe it'd be a
> different situation today.
Incorrect. I was there! And trust me when I say that 2012 Rust was very far off the mark. Rust is a language that was designed to be released in 2014, not 2012 or 2006 or 2038. > Almost all of Mozilla's major projects, from
> Firefox, to Thunderbird, to Firefox for Mobile, to
> Persona, to Firefox OS, and even Rust are suffering
> from some pretty serious detachment from the needs
> of their users.
Citation needed. By any estimate, Firefox still has a fifth of all web traffic, with 500 million users. Firefox for Android has between 50 and 100 million downloads and is the highest-rated browser on the Android app store. Firefox OS continues to find new carriers and launch in new territories, which is more than can be said for Tizen or Meego or Symbian or Ubuntu Touch. And even though Rust hasn't even launched yet we're seeing month-over-month growth in traffic on every outlet.Your narrative really needs some rethinking!
It has taken time to stabilize Rust because it is doing something that no language in industry has done. Rust is not designed to be a Go that's 10% better or a C++ that's 10% better. It's designed to let you do things you can't do in those languages. Like writing libraries callable by C that are guaranteed not to segfault. Or writing games that can't afford GC.