Is the browser safe?

Mozilla announced yesterday its BrowserID authentication system , based on the Verified Email Protocol . It looks pretty elegant, but is it safe?

One problem that immediately comes to mind is that it seems that anyone who can access my browser can log in like me. This is a problem with saving credentials in the browser, except that I can make this decision based on the site. Is it all or nothing with BrowserID?

Are there other potential security flaws?

+4
source share
2 answers

This is not a direct answer to your question, but there is a thread on the security exchange site that discusses the same

https://security.stackexchange.com/questions/5323/what-are-the-downsides-of-browserid-compared-to-openid-oauth-facebook

+2
source

In the end, I found that Daniel contributed to the third Q&A on BrowserId / Persona and WebID . I found this answer most helpful. (I tried to convince him to publish here, but he suggested that I do it.)


Security, privacy, and usability requirements for federated identity by Michael Hackett and Kirstie Hawkey provide a comparison between WebID and Mozilla Persona, which was still referred to as BrowserID for the time being.

The main differences noted in table 1:

  • Private keys are short-lived and must be password protected. WebID keys are durable, but can be easily disabled from a password-protected profile.
  • The current Persona implementation uses standard browser windows, so it is difficult to detect spoofing (this may change after browsers get Persona Persona support). WebID uses a user interface to select its own browsers, so there is no phishing.
  • Persona's identity and WebID may be compromised if the owner's email address / URI is lost.
  • Persona IdPs are unaware of SPs that use an identifier. WebID IdPs know every SP that uses an identifier.
  • If Persona SP has an IdP public key cache and the browser still has a valid certificate, you can still verify the identifiers. WebID profiles must be accessible, otherwise identifiers will not be used.
  • Persona has a good UX design, while WebID is the other way around.

I suggest reading the article in more detail. It is freely available on the Internet, access to the digital library is not required.

+1
source

All Articles