lecture: Persona: a federated and privacy-protecting login system for the whole Web

Websites that need to identify their users commonly use one of two methods: a username & password scheme that's hard to secure and creates a lot of pain for users, or a centralized proprietary service on which many of their users already have accounts.
There must a better way. A cross-browser solution for authenticating users which feels like the Web and preserves the decentralized architecture necessary for an open network. We present Mozilla Persona.
Passwords are a big problem online and a lot of websites have turned to centralized services to handle logins for them. It's a disturbing trend from a privacy/surveillance point of view, but from a software freedom point of view, it's also turning these proprietary services into core dependencies and expanding the walled gardens.
That's why Mozilla is building Persona, a new federated and cross-browser system which makes identity a standard part of the browser. It's simple, privacy-sensitive and entirely Open Source.
This talk will explore the challenges of the existing Web identity solutions and introduce the choices that were made during the development of Persona.
It will cover:
- a quick overview of current identity systems on the Web
- a discussion of the complexities and privacy-related concerns that existing identity solutions have
- how crypto is used to provide both authentication and privacy, even from your identity provider
- the Persona federation approach: fully distributed with fallbacks
- the importance of building a cross-browser system that works on all your devices
- demos and actual code from sites that have implemented Persona
- the basics of the Persona API so that attendees can go out and support this technology on their own sites
Identity is a very significant piece of Internet infrastructure and so it's critical that the solution that gets widely adopted be free-as-in-freedom, decentralized and ruthlessly focused on making it easy for developers and end-users.
Info
Day:
2013-08-24
Start time:
11:15
Duration:
01:00
Room:
HS1/2
Track:
Web Development
Language:
en
Links:
Feedback
Click here to let us know how you liked this event.
Concurrent events
- HS1/2
- Persona: a federated and privacy-protecting login system for the whole Web
- HS5
- ArangoDB
- HS4
- Samba4
- HS3
- SmartSarah
- C118/PHP
- Fixing legacy code
- C117/Java
- Praktischer Einstieg in die Android-Entwicklung
- C120/Django
- Django -- Eine Einführung
- HS6
- Can we write perfect tests? - Maybe!
- C175/FrogLabs 1
- Einführung in die Programmierung mit Python
- C116/Lisp
- The world as S-expressions
Speakers
![]() |
François Marier |