Talk:Mozilla Persona

Latest comment: 6 years ago by InternetArchiveBot in topic External links modified (February 2018)

Change of name

edit

BrowserID now appears to be called Mozilla Persona. I would suggest that this page be renamed. Jonathanmjefferies (talk) 14:16, 31 July 2012 (UTC)Reply

  DoneTom Morris (talk) 13:54, 18 August 2012 (UTC)Reply

Not sure that was such a good idea - indeed, BrowserID remains the codename for the protocol and Persona.org is the service ran by Mozilla.org, not the protocol itself. --TheAnarcat (talk) 02:52, 27 June 2013 (UTC)Reply

Secure

edit

Just because marketing material says something is secure, that doesn't make it secure. "Secure" is an unachievable perfect state, like "indestructible". We can only talk about the threats that have been anticipated, and the defenses against those threats, and the probability that the defenses will be breached.

For example, Mozilla's demonstration site https://login.persona.org/signin says:

We're sorry, Persona requires that Javascript is enabled.

Since Javascript is essential for successfully exploiting the vast majority of attacks on browser vulnerabilities, along with Cross Site Scripting which is still on the OWASP top ten vulnerabilities after 14 years, the best way to "secure" (better said, improve the security of) your browser is to disable scripts. (See NoScript.) Therefore if Persona requires one to lower their browser's security defenses, Persona is thereby forcing a reduction in the security of those who are informed and care about it.

Javascript will be "secure" when browsers are "secure", which, based on the track record of the last 20 years, will be approximately never. 129.219.155.89 (talk) 17:11, 4 February 2013 (UTC)Reply

Complete bollocks - a protocol designed to be secure is a secure protocol whether or not implementations are secure. To say it is not would be like saying there is not a road between Leeds and Manchester because they could be closed occasionally. By your argument you could say that there is no such thing as web security. -- Q Chris (talk) 11:22, 11 February 2013 (UTC)Reply
Can you show me a "secure" implementation -- one that can be used from a browser that is in "secure" (i.e. no script) mode? 129.219.155.89 (talk) 18:54, 11 February 2013 (UTC)Reply

I am once again removing the unsupported (original research?) claim that this is "secure".

  1. Nothing "is secure". There are only varying degrees of more secure or less secure.
  2. The only support for the claim is the vendor's web page, which is not an objective independent encyclopaedic source.
  3. The burden of proof is on the person making the claim, not the person challenging it.
  4. I have explained why I consider it inherently insecure, in that the reference implementation forces you to weaken your security, if you have taken appropriate steps to protect your browser and your identity. A road closed is not a good analogy. A better analogy is if you install some software that claims to "be secure" but it requires you to disable your anti-virus. That's what NoScript is -- anti-virus for your browser. Anyone who said their product only works with anti-virus off, but calls it "secure", would be laughed out of any gathering of security professionals.
  5. In reinstating the "secure" claim, an editor commented "it would be a bit strange if it wan't secure". That's reasoning by incredulity. "It must be true, because I just can't believe it could be false!"

Before reinstating the claim please cite an independent reference. 129.219.155.89 (talk) 14:23, 2 April 2013 (UTC)Reply

The argument that anything using JS is inherently insecure because JS can also be used to do insecure things is an extremely tenuous one. There are many vulnerabilities in Windows, which can be avoided by not installing Windows on your PC; it would however be a rather extreme position to say that no software can be secure if it requires Windows. - IMSoP (talk) 00:29, 20 December 2013 (UTC)Reply
I'll go one step further and say no software can be secure, period. This is because there is no such state as "secure" that you can achieve. As previously noted there are only varying degrees of more secure or less secure. 129.219.155.89 (talk) 18:37, 12 June 2014 (UTC)Reply
edit

Hello fellow Wikipedians,

I have just modified 8 external links on Mozilla Persona. Please take a moment to review my edit. If you have any questions, or need the bot to ignore the links, or the page altogether, please visit this simple FaQ for additional information. I made the following changes:

When you have finished reviewing my changes, you may follow the instructions on the template below to fix any issues with the URLs.

This message was posted before February 2018. After February 2018, "External links modified" talk page sections are no longer generated or monitored by InternetArchiveBot. No special action is required regarding these talk page notices, other than regular verification using the archive tool instructions below. Editors have permission to delete these "External links modified" talk page sections if they want to de-clutter talk pages, but see the RfC before doing mass systematic removals. This message is updated dynamically through the template {{source check}} (last update: 5 June 2024).

  • If you have discovered URLs which were erroneously considered dead by the bot, you can report them with this tool.
  • If you found an error with any archives or the URLs themselves, you can fix them with this tool.

Cheers.—InternetArchiveBot (Report bug) 08:56, 7 February 2018 (UTC)Reply