Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The biggest problem with Mozilla's Persona is the branding of it. Until they are able to get a handle on the branding-related issues, it can't get off the ground:

* Logo is ambiguous and looks like a generic button

* "Mozilla" in the name instantly steers away other browsers

We've implemented it on LinkUp (https://www.linkup.com/account/), love the technology, and REALLY hope the adoption of it takes off - but until I can explain it to a user in 2 sentences, it won't claim the throne.



You are so right. I implemented browserid when it was named "BrowserID" and it really made better sense (the name was pretty self explanatory). "Mozilla persona" sounds like something that only some obscure subcult of firefox users should use.

I would urge mozilla to remove all branding from the popup. It's gonna get really confusing when 3rd party popups get into the game (would they call it Google browserID or "google's version of persona"?). Second, since websites are not getting any private information from mozilla, mozilla is barely relevant. Third, while mozilla's work is commendable, users don't need a link to learn about the protocol and that it's benevolently "built by a nonprofit", instead they trust that the target website knows what it's doing by showing that popup.


98% in agreement.

I think the "built by a nonprofit" is a fantastic point that they should keep pushing, though.


To pile on, I thought 'persona' was an addon by which I could make firefox look different.


Exactly what comes to my mind. "[…] easy-to-use themes that let you personalize the look of your Firefox."[1]

[1] http://www.getpersonas.com


It's also a movie by Bergman


It's also a series of Japanese role-playing games.


There is a really easy way to explain Persona to users:

"Sign in with your email address"

At Voost (https://www.voo.st/) we have been using BrowserID since launch earlier this year. We just use this simple phrase and users "get it" right away. There's no need for complicated branding.


Except this would only work if you:

1) Forced all users in your system, who already had email/password based accounts, to abandon their existing accounts and adopt Persona

2) Became fluent in quickly explaining to users how to reset their Persona password when they forget it

3) Don't mind losing all the users who say "I trust you, but not this company I haven't heard of before." Some users, especially jobseekers, won't let their circle of trust grow - and forcing adoption of a 3rd party causes abandonment. But so does a complicated sign-in process, so you just need to figure out if group A or group B is larger because you can't make everyone happy.


#1 makes no sense. If you already have email-based accounts, switching to Persona is trivial - you just switch to Persona auth and everything works as-is with email as the account key. You will of course want to give users a little warning, but the process is far simpler than almost any other change you can make to your authentication system (eg, deconfliciting usernames). The only real change when switching to Persona is that you drop your stored password. It's still "sign in with your email address".

#2 has not been a problem, as far as we can tell. If users forget their passwords, the reset-password process on the Persona login dialog works great - better than almost every other password-based website I've used. In the long run, passwords are only maintained by primary IdPs like Gmail, so this is even less of an issue.

#3 is totally dependent upon your audience. We definitely get pushback on Facebook auth - you can't run a FB-only login system without alienating a significant chunk of most audiences. Initially we tried to encourage FB auth by making BrowserID less obvious, but that just produced a lot of angry emails from people who didn't realize they had an alternative. Now that Persona and FB auth are on equal footings, we have yet to have anyone complain about the signup process. YMMV.


Which email address? And what (else) will I be signed into?


If Chrome and Google+ support Persona, they would validate the system and get an advantage on Facebook.

Facebook blew it. They could have been identity for the internet, but with all the privacy and spam problems users HATE logging in with Facebook connect. We tried it for a website and it just failed. There's huge resistance.


I just tried to login into your site without being registered with Persona. All works fine, I can choose a password, and receive an email with confirmation link. When I click it I see an info box from Persona, but after only 3 seconds or so I get redirected to your site - so that is buggy. I see then a notice that your site couldn't log me in, which is fine, as I don't have an account. However, your site then starts to log me in over and over again. Which seems an issue on your site. Hope this info helps. I'm using chrome on OS X.


Thank you so much for the thorough details. I squashed this bug. Can you ping me at eric@linkup.com so I can send you a Starbucks giftcard for your help?


> We've implemented it on LinkUp (https://www.linkup.com/account/)

What's your experience with that? Implementing OpenID tends to not be very fun (whether as a consumer or as a provider), is Persona better?


I did OpenID early on in the site (nobody understood it), RPXNow/JanRain (more than we could afford for fewer features than we needed), and finally our own solution that does OAuth* for the various providers and Persona.

I love Persona. I want a Persona shirt and tattoo. OpenID was just a bit harder, but had nowhere near the payout that using Persona offers. The only burden of Persona is the auto-login/logout handling, which is a good thing in the long-run but in the short-run involves tracking down all your login/logout methods and making sure they all react properly.

*OAuth integration is a nasty mess of nastiness that I can't bring up w/o derailing this entire conversation. If you want to chat about that train-wreck, email me.


I also adore Persona. It took me two minutes to integrate on my Django setups the first time, and less than that on subsequent ones. Nowadays, it's all I use.


Not the GP, but I was thrilled with how easy it is to integrate. I have a little site that I'm putting together as a hobby, and it took me about an afternoon. Web development isn't my specialty, so if you know what you're doing you could probably do it in less than an hour.


Those expanding buttons on hover are terrible. a) hover is useless on a touch screen device. b) it feels like a moving target.

I'm curious how you deal with someone logging in with one system and then coming back and logging in with another. Do you have a way to merge accounts somehow?

Also, I clicked on yahoo and got this: http://www.evernote.com/shard/s178/sh/faba70e1-03e6-4448-81f...


Thanks for the feedback. We're still working on nailing the design - we need a way that all the buttons look uniform, and want a way to explain what they are (namely Persona, as I said, still working on it.) And fitting the multiple options in the small space is no easy feat. Fortunately hover isn't necessary for interaction, so the touch screen device point is moot. And the "moving target" is the same reaction as people gave Apple's dock. But you're right - this design isn't perfect yet.

Once a user's source authenticity is verified, we give the option to merge accounts once we detect overlaps. So if you login via Twitter, verify your Yahoo! email address through the profile, and then login through Yahoo!, you'll be in the same account as you were in the 1st login. We have ~20 scenarios that we maintain for logins, and have heard 0 complaints on the assumptions we have in practice.

Thanks for the screenshot - we'll get that fixed today. Would you like an email once it is resolved?


[deleted]


Let's agree to disagree on this point and let this thread end.


Yahoo! login bug has been fixed.

Teaches me to try and get Yahoo! to behave with https. If anyone wants a great example of why to use Persona, try using Yahoo's developer apps interface...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: