Virya Technologies Blogs

Blogs from Virya Technologies staff

Posted by Ruth Cheesley
Ruth Cheesley
I am the owner and Director of Virya Technologies, with the responsibility for leading the website design team...
User is currently offline
on Friday, 22 July 2011
in Website design

An alternative to multiple usernames and passwords for websites? Mozilla suggests token free BrowserID system

Sticky notes are frowned upon .... excel spreadsheets can be compromised ... and my memory is about as good as a leaky sieve!  Mozilla appears to have come to the rescue with a suggestion of a future alternative to the hundreds of username/password combinations we have to remember if we're keen users of websites.

Calling it BrowserID, Mozilla announced this week that an alternative way of identifying with websites was in the pipeline, and encouraged web developers to look at implementation.

What was that password again??

Like many, I frequently stare gormlessly at a website running through the various systems I use to generate usernames and passwords before I have any clue of what the credentials might be for that particular site.  Frequently, it's quicker for me to admit defeat and use the password reset feature!

BrowserID sounds as if it could remove this brain-strain permenantly (hurrah!)

One email, one login

Users of BrowserID would need to set up their email address to generate the 'key' to get into the authentication system and verify their email address.  Subsequently, any sites which support BrowserID login would simply require the user to click on the BrowserID button and select their registered email address from a menu.

The geeky bit

The BrowserID system proposed by Mozilla is built on top of a new 'Verified Email Protocol' which uses public-key cryptography to identify the email address of the user.  Behind the scenes, the service creates a cryptographic key pair once the user confirms their email address, storing the private key with the browser and hanging onto the public key.

The user can register more than one email address (e.g. a private email for 'personal' stuff and a corporate email for 'business' stuff) and when the email is selected to allow logging into a site, the appropriate key is retrieved to verify their identity.

Isn't this just like OpenID or signing in with Facebook, Twitter, etc?

It is, and it isn't.  The concept is the same (using an existing service to authenticate to a new service) however this system requires minimal input from the user, after which the login process is literally one or two clicks.  The other thing to consider is that outsourcing to companies such as Facebook and Twitter your login procedure, you are relying on their systems being online and available.  Also you don't have much say in what gets developed.  BrowserID is open source.

What about security?

There are some security issues which haven't quite been resolved yet - one example is that a system administrator could take control of a users' email account (but this risk would be inherant for other systems too, but this becomes more of an issue if it is used alone as the authentication method without a requirement of a username/password).  It would also raise email hacking attempts to a whole new level if this was used as the sole means of authenticating to websites.

BrowserID is, however, written entirely in HTML and Javascript, and Mozilla are clearly stating that this means it does not leak any data back to any server about which sites you visit when using the system.

Get playing!

Mozilla are keen for developers to get involved in testing and potentially contributing code to the BrowserID project - you can visit the project website at https://browserid.org/.  Please note this system is still in its infancy and we would not recommend its use on live sites at the present time!  It looks like it could have great potential if the issues are ironed out.

Rate this blog entry
I am the owner and Director of Virya Technologies, with the responsibility for leading the website design team.

I am primarily involved with the day to day management of our website projects, ongoing support contracts and liaising with our clients from across the world.
Trackback URL for this blog entry

Comments

Guest
web tasarım Monday, 25 July 2011

awesome article very nice post about browser id system ,thank you

Leave your comment

Guest
Guest Tuesday, 22 May 2012

Looking for our open source software?

viryasoftwarelogo

We release and support our open source software at Virya Software

Find us on

facebook    linkedin    twitter     youtube    vimeo    ViryaTechnologiesJoomlaResources    ViryaTechnologiesonTechnorati    rss

Virya Technologies Newsletter

Receive all the latest tips, news and reviews from Virya Technologies.

Come and meet us!

JUN
01

01.06.2012 07:30 - 09:30
Ipswich Connected Business Breakfast

JUN
01

01.06.2012 12:00 - 17:20
Ecademy BlackStar First Friday Working Lunch

JUN
14

14.06.2012 19:30 - 22:00
Joomla! User Group Suffolk Meeting

JUL
06

06.07.2012 07:30 - 09:30
Ipswich Connected Business Breakfast

JUL
06

06.07.2012 12:00 - 17:20
Ecademy BlackStar First Friday Working Lunch

The latest from Virya Technologies

Virya Technologies After an awesome #jab12 event we are offering 20% discount on all extensions until 7th June - use JAB12 coupon code at http://t.co/XrDJFRbq
Monday, 21 May 2012 07:46
twitter Follow Viryatech on Twitter