Identity/Department Status/2013-10-10

From MozillaWiki
Jump to: navigation, search

Hi Everyone,

Welcome back from Summit 2013. There is a lot of activity with our projects, and the team is working tirelessly.

Identity Status Report for Sept 30 - Oct 11

Let's kick off with some news:

Introducing Firefox Accounts Firefox Accounts is a safe and easy way to log in to applications wherever you use Firefox. Firefox Accounts is not just another silo. It is powered by Persona, to let you use the identity you already have, wherever you need it, and skip the social spam.

One of the first services attached to Firefox Accounts will be Sync. With Sync, you don't need to worry about your browsing experience being stuck on one computer. By logging in with your Firefox Account, your open tabs, awesome bar, and bookmarks will follow you wherever you use Firefox.

<Updated for Q4> Identity Department Focus:

  • Persona: An open authentication system for the web gives you the fantastic convenience of social sign-in, without sacrificing your privacy.
  • Firefox Accounts: A single account, built on Persona, that brings a growing ecosystem of useful services to any firefox user.
  • Sync.next: The new Sync - it does what you expect, its built on Firefox Accounts, and lets you access your data wherever you are.

For more information related to all Identity projects: https://wiki.mozilla.org/Identity

Signin Project Overview:

  • Persona is designed to eliminate website passwords and empower users to choose their own identity online.
  • It's long term goal is to become a standardized and browser-native means of decentralized authentication on the Internet.

Current Status:

  • The team discussed, designed, and prototyped a new, simpler, and mostly stateless API for Persona which will dramatically ease integration into existing frameworks and websites.
  • Deployed several hotfixes to address security issues discovered (and responsibly disclosed) by researches at Universität Trier. From reviewing our logs, we do not believe that any users were affected. Disclosure: https://blog.mozilla.org/security/2013/10/02/learning-from-a-recent-security-vulnerability-in-persona/
  • Suspended work on cross-domain single-sign-on: upcoming changes to browsers including Safari on OS X and iOS currently make implementation impossible.

PiCL Project Overview:

  • PiCL stands for Profile in the CLoud
  • It has two major efforts: Firefox Accounts and fixing Sync
  • Firefox Accounts are a safe and easy way to connect with Mozilla and non-Mozilla services across all of your devices -- laptop, phone, desktop or tablet -- so you have access to the services and data you need, whenever you need them, from wherever you are.
  • One of the first services attached to Firefox Accounts will be Sync. With Sync, you don't need to worry about your browsing experience being stuck on one computer. By logging in with your Firefox Account, your open tabs, awesome bar, and bookmarks will follow you wherever you use Firefox.

For more information:

Native B2G & FXOS Project Overview: B2G: Sign-in on First-run

  • We are building Firefox Account creation into the first-time use (FTU) on FirefoxOS. When users unbox their phones, they will provide an email and password. From this, we will create a Firefox Account for them that will give them an identity for use with Marketplace and future cross-device services, like synchronization of bookmark, history, password, and contacts data. Additionally, we will provide an account management app where users can revise their account settings.

A single place for native implementation overview, status, and teams: https://wiki.mozilla.org/Identity/Native_Implementations

Current Activities:

  • Reminder: new dev-fxacct mailing list for communication (please join if you're interested!)
  • Work week scheduled 21 - 25 October with Identity & TEF engineers. The focus is on the First-Time Use experience (FTU).
  • Ongoing work on b2g bugs

Persona Analytics Project Overview: Measuring Persona: User adoption, website adoption, error discovery, etc.

Current Activities:

  • Dashboard updated with bugfixes
  • Several PRs landed adding the new data streams

For more information about our metrics effort, visit our Persona Analytics page, and KPI Dashboard [LDAP required].