Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Replying to drivebyacct2, nope, the protocol doesn't expose where you log in (that was one of their explicit goals). It's also one of the reasons I like Persona so much and decided to make this.

I'm very glad you like it, I am always looking for feedback and would love to see Persona/Persowna gain more users. Please don't hesitate to email me about anything (email is in profile).



the protocol doesn't expose where you log in

To be fair, in practicality it does expose where you log in because that website has to communicate with the persona server. The website could use a proxy or something to try to obfuscate which website it is doing an authentication for, but if there is any significant volume it would surely leak out unless they did it through Tor (and were not the only site doing persona authentication through Tor either).

What the persona protocol explicitly does not leak is each login event, checking in with the persona server only happens once during account setup.


The website grabs a single certificate from the persona server the first time it sees a particular e-mail hosting domain; all this reveals is that someone in that domain (no specifics as to who) tried to log in at the beginning of the lifetime of that certificate in the cache. Until the cache expires, an arbitrary number of users can log in to the site without any communication touching the persona server. It doesn't reveal who logged in, when in the cache lifetime they logged in, or even how many people logged in.


At most that certificate is good for 24 hurs. The user has to get his assertion signed by the identity provider too, and it is possible to get them pre-signed up to that same 24 hours. So the window of users is narrowed to the list of sites that queried the identity provider and the users who had an assertion signed within those 24 hours. Which is weakly anonymous for high-volume sites and no protection at all for low-volume cases.

However, the kicker is the protocol doesn't protect against the identity provider setting the expiration to something like 5 minutes, effectively unmasking the client and the website by requiring them both to talk to identity provider within that 5 minute window.


Hmm, does it? It's been months since I implement the spec, but, from what I recall, you hand the signed assertion to the user and they present it to the site. Am I wrong?




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: