- Progetti & Gruppi di lavoro
- Calcolo scientifico
- E-Infrastructure for E-Science
- Cloud Computing
- Learning Infrastructure
- E-Identity
- Gruppo di lavoro – ICT Law
- Gruppo di lavoro – Mail
- Gruppo di lavoro – Media
- Gruppo di lavoro – Rete
- Gruppo di lavoro – Aquisti IT
- Gruppo di lavoro – Sicurezza
- Gruppo di lavoro – Storage
Mozilla Persona
16 ottobre 2012
Mozilla has just released the beta version of their authentication system Persona. It effectively allows internet users to log in into web sites with just one password. The authentication system is based on BrowserID, and it involves three parties: the user (and his/her browser), the resource provider and the indentity provider. All three parties have to support and implement Persona. Before you say "this is never going to happen": the nice thing of the Persona today is, that it can be used right away if the the resource provider (the web site requiring a login) supports it, because Mozilla provides a fallback IdP as well as a javascript library to top up browsers. The advantages for resource providers are:
The disadvantages for the resource providers:
From the perspective of the user the advantages are:
And the disadvantages for the user, apart from the fact that there are only very few Persona-enabled resources:
Persona is an interesting concept, and I will try to use it as a user and as a resource provider in a small test site. Mozilla has found a way to use public key cryptography for user authentication without revealing it to the user. From the three prerequisites (browser, resource, identity provider) I guess the IdP is the most tricky part. First, the mail providers have to develop a business model and second, the quality of their service determines to a large extent the quality of the entire Persona authentication ecosystem. Rolf Brugger |
|
| Link: | |

