Mozilla Releases BrowserID Web Authentication System
Mozilla has released a new browser-based federated login mechanism called BrowserID that is designed to replace the login process on Web sites that requires users to supply an email and password. The experimental system relies on the Verified Email protocol and also works on other browsers, including Internet Explorer.
For users, the BrowserID system works fairly simply. In order to register with the system, a user enters an email address and password one time and then clicks on a link in a confirmation email, just as she would in a typical Web site sign-up process. Once the user has confirmed that she owns that email address, she can then use it as her mechanism to sign in to any site that supports BrowserID, simply by clicking on the BrowserID button on the site.
The system is implemented in HTTP and JavaScript on sites, and Mozilla officials say that the system is designed to respect user privacy and not leak any data back to the sites involved.
Editor's Pick
"An email address with a confirmation step is the classic method, but it demands a user’s time and requires the user to take an extra step and remember another password. Outsourcing login and identity management to large providers like Facebook, Twitter, or Google is an option, but these products also come with lock-in, reliability issues, and data privacy concerns," Mozilla said in its introduction of BrowserID.
"With BrowserID, there is a better way to sign in. BrowserID implements the /verified email protocol/, which offers a streamlined user experience. A user can prove their ownership of an email address with fewer confirmation messages and without site-specific passwords."
Creating and remembering passwords for the dozens of sites on which they're registered has become a major problem for users. As a result, many people re-use passwords, weakening or eliminating whatever small modicum of security they provided to begin with. Mozilla said that the BrowserID project is in its early stages and will likely evolve over time.
Commenting on this Article is closed.
Today's Most Popular
- Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest
- Report: Diablo III Users Find Accounts Hacked, Gold Stolen And New 'Mystery' Friends
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- Why Google Won't Protect You From Big Brother
- Dear Jailbreaker, Apple Wants to Have a Word with You
Most Commented Stories
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




Comments
Hi,
Where can I find/download BrowserID?
Not a problem for me. I use Roboform to remember my secure passwords.
Browserid.org has all the info, but it's not something you download. It's implemented on sites and once you register on one, you're good on all of them.
How it this different than OpenID?
wiedzmin, http://identity.mozilla.com/post/7669886219/how-browserid-differs-from-openid