TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Mozilla adopts plain-vanilla password sign-in for Firefox sync

34 pointsby hiburoover 11 years ago

8 comments

josteinkover 11 years ago
I see this as a reaction to the competition they&#x27;re facing with Google Chrome.<p>With Google Chrome you log into your Google account. email + password and all is good. It&#x27;s <i>simple</i>, but fundamentally insecure. Google, NSA and whoever else they partner with can poke at all your data without restriction because it is based on a centralized authentication model.<p>Firefox always based its sync on a <i>secure</i> model where no data was stored unencrypted at Mozilla&#x27;s sync-servers. There was no traditional &quot;account&quot; which Mozilla had to validate. You could also chose to use your own sync server. Either way, they can not peek at your data.<p>You gave Firefox your email and a &quot;password&quot; and from that it generated some private keys used to encrypt the data sent to Mozilla. Private keys which you then had to distribute to other Firefox&#x27;es one way or another.<p>They attempted to ease the pain by having some &quot;pair this device&quot; wizards with 3 simple values you could copy from device A to device B, but in the end it still meant that the superior security came at a cost.<p>No non-technical people I know use Firefox&#x27;s sync, but everyone I know who use Chrome also use its sync feature.<p>When comparing browser, some people literally list out &quot;sync&quot; as thing Chrome does and Firefox doesn&#x27;t. That tells you a lot about how a simple and in your face implementation can drive adaptation. (I think Chrome&#x27;s approach is too in-your-face, but that&#x27;s another discussion.)<p>I honestly believe Firefox&#x27;s original model is superior once you get past the initial warts, but I can see why they are making the changes they do.
评论 #7169969 未加载
评论 #7169709 未加载
blueskin_over 11 years ago
Will Mozilla be removing the secure sync option or having this one in parallel?<p>I don&#x27;t use it myself, but it&#x27;s definitely worrying to see a secure option being potentially removed in favour of plaintext storage on servers outside the user&#x27;s control.
评论 #7169754 未加载
评论 #7169980 未加载
评论 #7170232 未加载
tarkin2over 11 years ago
Now all my bookmarks, history, passwords and the like will be stored on a centralized server?<p>The decentralization, especially in the wake of the NSA&#x2F;GCHQ revelations, was one of its main advantages.<p>Sigh. I may well have to turn Firefox sync off then.
评论 #7170337 未加载
评论 #7170322 未加载
评论 #7170030 未加载
icebrainingover 11 years ago
The actual announcement from Mozilla: <a href="https://blog.mozilla.org/futurereleases/2014/02/01/test-the-new-firefox-sync-on-nightly-release-channel/" rel="nofollow">https:&#x2F;&#x2F;blog.mozilla.org&#x2F;futurereleases&#x2F;2014&#x2F;02&#x2F;01&#x2F;test-the-...</a>
zokierover 11 years ago
Not Mozilla Persona? Why wouldn&#x27;t it be suitable for this purpose?
评论 #7170327 未加载
评论 #7170428 未加载
yetfeoover 11 years ago
What is the &#x27;Firefox Account&#x27; the new sync system uses and how does it differ from Persona? Will I need a &#x27;Firefox Account&#x27; for other Mozilla services? What about Firefox OS? It seems bizarre to me to have this additional account system while promoting Persona as the system for other people to use. Is Persona abandoned?<p>Edit: the article mentions a Firefox Account is needed to use the Firefox Marketplace too. That&#x27;s a webapp which I thought would have suited Persona.
评论 #7170628 未加载
option_greekover 11 years ago
Aah good riddance to the older approach. Its a major fail from UX perspective. The long sync key was ridiculous to type.
评论 #7169722 未加载
评论 #7169877 未加载
评论 #7169713 未加载
ksecover 11 years ago
I wonder if they would update Firefox Sync on iOS. Since it is pretty much dead.