Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The statement that Mozilla should have issued:

"Some have claimed that we should move Mozilla out of the US. Unfortunately, for reasons of connectivity, workforce, ties to US market, legal issues and restructuring costs we are not able to do that.

Current (recurring) developments in the US have shown that our government can not be trusted. No amount of legislation is going to achieve a fully accountable government.

Because of this, we are unable to guarantee that Persona is or will be exempt of data requests from one of the government agencies. Even worse: we will not be able to tell you when / what data has been requested. We are and will not be able to confirm or deny data requests. It can be that future legislation forbids us to even make the statements that we are making in this paragraph, so this is maybe the last time that we can tell you this.

The only solution to a private internet is to fully embrace cryptography for all our communications. Until then, you can use Persona at your own risk."



The last bit here is a reach. For starters, Persona uses SSL, so it's encrypted. But more broadly, if you're going to use centralized, third-party authentication mechanism you could do far, far worse than Persona. I'd go so far as to say if your site is implementing its own authentication system, you could do yourself even more damage with a poor implementation.

Your critique seems to missed an important part about Persona's design: "It’s also worth pointing out that we do take certain technical measures to limit the data we collect. We’ve designed Persona so that the identity provider – including the fallback Identity Provider that we run – does not learn your browsing history. We consider that a good security practice, not specifically because of surveillance, but generally because collecting data without a user benefit just creates risk."

Further, the main "centralized" risk would be their default identity provider. If you don't want to use that for your domain, you can provide your own, and host it in another country. In this case, Mozilla's servers aren’t even being contacted when you authenticate.


I know nothing about Persona. I have never used, and I have not read anything about it. But that much is clear to me: the communication between you and the Persona provider can happen very much over an encrypted channel, but the data in the Provider is not encrypted with a key which you only know. The Persona provider has the data in the open (except passwords, which are hashed)

This whole fiasco has shown a weakness in the system which was there all the time, but little acknowledged: it is not about encrypting communications anymore. The eavesdropping risk is well understood and there are technologies available to get rid of it (SSL, SSH tunnels, whatever). But now we need to encrypt the data everywhere. Nobody can be trusted with the data anymore because the government can be accessing that data, and they do not need to eavesdrop: they just need to send a letter and implicitly threaten with litigation and imprisonment to obtain whatever data they want.

This makes the technological solutions much more challenging, and some services can probably not be provided. How does Facebook provide services to their users if the data they have must be encrypted and they can not access it? How to share with friends photos if they are encrypted? Maybe creating ad-hoc group passwords to share data? I do not know, it is difficult.


Dude, what the hell are you talking about?

The only thing those in power would find out by looking at Mozilla's servers in charge with Persona authentication would be your freaking email address and that's it. This is by design.


"It’s also worth pointing out that we do take certain technical measures to limit the data we collect. We’ve designed Persona so that the identity provider – including the fallback Identity Provider that we run – does not learn your browsing history."

That does not say "we only store your email address". It also does not say they are storing more than that, either. In any case, the data is not encrypted, so my argument stands.


You should read up on what Persona is before making judgments about it. Just a general guideline for reasonable discourse.


Here: http://www.mozilla.org/en-US/persona/

"Many sign-in systems carry your profile data with them; some even share that info with other sites and social networks. We believe you should control how your personal information is shared. Persona lets you get started with just your email address; you can add your profile data later, when and where you think it’s appropriate."

Whatever that "profile data" is, can be requested by the government.


The "profile data" that refers to is the profile data you want to add per-site. It's got nothing to do with Persona.

All Persona knows is your email, a password and the fact that you (maybe) want to authenticate at some point (but it doesn't know where, and it can't be sure you're actually trying to authenticate somewhere even).



> The only solution to a private internet is to fully embrace cryptography for all our communications.

Mozilla (or at least the Mozilla employee that wrote the OP) does not believe that: http://benlog.com/articles/2012/04/30/encryption-is-not-grav...

Personally, I think that argument is right. "Complete" encryption has usability tradeoffs many people will refuse to make. And I get that. Emotionally, it frustrates me that I can't store my Google Authenticator key in Google Drive even though I understand exactly why that would break two-factor authentication.


Plus:

"Some have called on us to move Persona servers outside the US..."

But: "We’d rather focus on efforts to change the Law to respect user data wherever it lives."

What?! Who says it's an either-or question? IT'S NOT! IT HAS NEVER BEEN!

ANY and ALL means must be used, given the gravity of the situation!


The blog post doesn't say it's an either-or question. It says that, given that Mozilla has limited resources, we think it is more effective to focus those resources on changing the law to benefit the user rather than trying to fix just Persona by moving it to another country.

If we had unlimited resources than we'd be able to do both, but the post goes on to explain why that wouldn't be effective anyway.

(Disclaimer: I work for Mozilla in a different department than the Persona team.)


Honest question: why the wishful thinking? Why not tell it like it is? What is the potential damage that Mozilla could suffer by clearly stating that it is impossible and it will be impossible to guarantee that the government will not be monitoring all online activity? We know that the shadow-government is very good at:

1) Spying its citizens, using legal or illegal methods.

2) Cover up those operations with the use of force (indoctrination, legal threats, imprisonments, ...)

3) Change operation procedures whenever a martyr leaks the modus operandi, and improve the sealing of those activities.

This has been going on for decades. They have been iterating on this for a long time and we can assume that the shadow-government is very competent at it, so it will be impossible to control it. It is not possible to reign on the secret machine anymore.

The latest improvements on the spying machine are:

1) Better understanding of the whistleblower phenomenon: how to better indoctrinate workers so that they are less likely to talk, how to assassinate the character by using the media, how to create an example by using the full force of the law (whatever that means in this context) to make the possibility of leakages in the future less likely, how to put pressure in other governments to aid in the prosecution of whistleblowers. They have had lately several high-profile cases (Manning, Assange) for testing their machinery, and it is working perfectly.

2) Coerce companies into collaboration, and at the same time legally forbid them to neither confirm nor deny participation. I must say that this is simply a work of genius.

Mozilla could at least openly recognize this fact, as long as this is still a legal thing to do. The next iteration of the spying machine will maybe not even allow us to have this conversation. Who does feel safe talking about this things anymore? Not me, for sure.

Mozilla could still in good faith recommend Persona, while clearly stating that they are in no position to make any guarantee whatsoever about possible monitoring activities.


We did tell it like it is. In the security reviews (note the plural; we have ongoing reviews).

Here is the documentation from the initial public release: https://wiki.mozilla.org/Security/Reviews/Identity/browserid

Note all of the times we called out government actors as potential threats?

With respect, it is easy to tuck tail and run (as in move to another country), it is much more challenging to dig in and try to change things.

(Disclaimer, I work for Mozilla, on the security team, and I worked on reviews of Persona since its first design iteration).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: