Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, most authenticated web services offer a "forgot password" option, and their security is thus tied to your email account. However, each one of these decentralized services on its own is not as valuable as the entire ecosystem of Persona-enabled sites will be.

That is, the Persona "forgot password" is a single point of failure which, if compromised, can provide access to a whole ecosystem of sites. And it will be tied to your email account.



I'm still not seeing a distinction. Your email account is already a single point of failure for every account registered with that email that has a "forgot password" feature.

Maybe it would help if we considered two hypothetical scenarios. A: Your email is compromised, and you're registered on 15 websites with that email, each of which has a "forgot password" option. B: Your email is compromised, and you've used Persona to sign into 15 websites. In what concrete, practical way is B a more damaging situation than A?


Great point! And the recovery process is much easier in the Persona case... because you only have to fight to get back your Persona account. Today you'll have to

1) Fight to get your email account back

2) Visit each and every site and manually recover your account




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: