Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, yes, you're right. Seeking a perfection usually means never releasing anything. That's spot on.

Yet, I'm particularly against about the BrowserID adoption because it helps to cement the idea of leased identities. At the moment, we're still with in the "warring states" world, where no particular scheme had won. This could've changed with BrowserID embedded in the User-Agent, so I fear it would be at least a decade until we'll be able to talk about something else.

WebID, being a W3C WG, could've also hit big... It's not perfect, but from my understanding of the drafts it looked better than BrowserID to me. But no luck here.



It's an interesting moral line in the sand you are making.

Persona/BrowserID simply reuses the concept of email address as identity (and email host as identity provider). This is honestly already pretty heavily cemented in the web (I think the war has long since been lost): almost every website uses in some way emails as natural keys for identities and with the critical overuse of email as the medium for "Forgot Password" login schemes, email hosts are already everyone's de facto identity providers.

At least there is more personal choice involved in email hosts, and indeed sometimes direct ownership in paid email accounts, unlike the walled garden monopolies we see in Twitter/Facebook/Google "social" logins.


Yes, emails are currently required on almost every site. I draw this line because BrowserID/Persona (and similar efforts) are quite special - we jump from the pages to browser's chrome, making user-agent actually handle authentication.

I think that the first major standard to come - that'd be embedded in the browser - could change this game rules, because it must be (well - I don't know, I just think it is) a big thing. Even users who don't care would've bought secure yet seamless authentication, neat identity management and so on. But not something after this, because the momentum would be lost and there won't be enough incentive to switch.

So, the first standard must have something sensible as credential, or - I fear - it will be a long time before we can hope for any changes. Maybe I'm wrong here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: