Hey Nukeador!
On Oct 9, 2013, at 2:34 PM, Rubén Martín <
nuke...@mozilla-hispano.org> wrote:
>
> After doing some research on the current status of Firefox Accounts I have a big concern.
>
> As far as I understand, my Firefox Account and my Persona account are going to be independent, two different passwords, and there is no way to log in with Persona to Firefox Accounts as it was planned at the beginning.
>
>
http://people.mozilla.org/~zfang/FirefoxAccount/PiCL_0905.pdf
>
> Is this still the case? If so, why?
This will be the case for the first engineering milestone of firefox accounts. However, we are going to be very careful to pave the way for future Persona integration. The key thing this requires is a strongly verified email address in the Firefox Accounts database - something we will have.
The reasons we just didn't go all in with persona as the only way to sign into FirefoxOS, Firefox Android, and Firefox Desktop are these:
1. Native integration of persona is required - this is in order to provide a really seamless sign up flow into the browser. This work is in progress, but not yet landed.
2. Checking your email in order to set up your new phone can be clumsy - we really need to think about and optimize the flow, and the identity ux team is working on this now, and firefoxos folks have some strong opinions too.
3. Firefox Accounts was initially designed with a laser focus on sync. In order to encrypt data, the goal was to have a password. Because we didn't want to bombard the user with multiple passwords, there was concern we couldn't have a usable experience unless we used a single password (and not persona).
4. There was concern that a third party during signing into your browser would be confusing.
All of those reasons led us to define a first engineering milestone which uses your email and a new password. As that first milestone is being implemented, our UX team is working in parallel to figure out how we can optimize the sign-in flow.
I'm optimistic at this point we can bring in persona / federated sign in, improve usability, and reduce the role of, or potentially eliminate the new password in firefox accounts, and make even better security tradeoffs.
Not everyone is as optimistic, but I'm a dreamer :).
lloyd