Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There is a token that's passed. The web site gets an email address and a string called "an assertion" that they must verify.

If Gmail suddenly started verifying instead of Persona for @gmail.com addresses, the web site would see the email address as exactly the same so should give access to the same account.

They would then start verifying that "assertion" using Gmail and not Persona. It would be verified and hence secure.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: