Hacker News new | past | comments | ask | show | jobs | submit login

Yes, if Google/Facebook/(whatever domain you want) provide Persona endpoints, the user would be redirected to that Persona provider to sign in to your site.

From what I understand, it's exactly the same workflow as Facebook Connect, except it's <each user's Persona/mail provider> Connect.




No, it's not the same thing. When you use Facebook Connect, your browser asks Facebook to provide relevant information to the site you want to sing in. As a result, Facebook knows about which sites you signed in and when.

With Persona, you ask the identity provider to sign a proof-of-identity for you, which the browser stores. Then you can use it to sign in to different sites as long as it's valid(it expires after a certain amount of time for security reasons). Your identity provider wouldn't know which sites you signed in. That's why it's called browser-id.

So yes, the workflow is almost the same, but it's much better for privacy reasons.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: