Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Having used Persona on my last project, I'd agree.

The article brushes aside the "no traction" bit and says, basically, "the idea was awesome". But that's why we test ideas and measure them by results like traction: not all great ideas turn into great products.

Persona as deployed was an appealing idea that did not provide a great user experience (or really, a great developer experience). To fill the gap, you need to A) deliver lots of value, or B) target an audience that has some special motivation (e.g., idealism) to use the product. Persona did not do A, and general-audience users definitionally lack B. A site's developers might have that motivation, which is why some people tried Persona out. But if the users don't share the motivation, then to them it's just a low-grade experience.

If Mozilla wants to go after the identity market again, they need to do something different. The obvious thing to do would be to leverage their browser market share and make something lower friction than existing systems, rather than Persona's higher friction. But since this is an obvious idea and there are plenty of smart people at Mozilla, I presume there's some good reason they didn't do that in the first place.



The entire point of "Persona" is that it was actually something in the backend called "BrowserID" that was supposed to integrate with the browser instead of running some random JS widget in a page. Well, Mozilla never even finished implementing the first version of that before they declared "no traction"! What nonsense!


Having native code handle something in the browser instead of a thin, easily verifiable javascript widget seems the opposite of a more secure solution.


You’re missing the point. Emphasis on “in the browser” not “native.”

http://www.extremetech.com/wp-content/uploads/2011/07/firefo...


No, because javascript puts the server in control of the code being run on the client. It renders the whole thing vulnerable to nasty attacks like spoofing and MITM.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: