Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From what I read (very very briefly), the spec is similar to what OpenID was, in that anyone who runs a web server can become an authentication provider. Ideally there'd be a distributed-hash-table type web-of-trust so its semi-centralized (i.e. somewhat like PGP or BGP routing tables where you peer with people you trust).

Now that 1st party browser certificates are available so you get that Trusty-Green-Lock(tm) on all browsers, geeks can theoretically run their own identity service based on some sort of combination of these technologies. (Ideally with the long term outcome solving the "Why Johnny can't have Crypto" problem, maybe using a cell phone app as an RSA SecurID type dongle.) This also has the benefit of letting you authenticate against your bud John's Identity Server, rather than Go-fuck-yourself-Fred's (you'd need token negotiation in there somehow though).

Someone smarter than me (DJB where are you?) should piece this together, release it as open source for the end-user, and fund it via expensive Exchange module integration.



I still run my own open id, but very few people support open id anymore. Slashdot removed support, shirt.woot removed support after the Amazon buyout ... The only thing I use that still supports it is stack overflow.


So I can have an authentication provider that is not an email provider and people can have accounts in my provider just to use them in Persona logins?


Yes, see https://persowna.net/. Setup is as easy as copying a file to your web server.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: