You are reading a single comment by @Velocio and its replies. Click here to read the full conversation.
  • The only potential downside is if you lose control of your email account.

    i.e. You used a work email to register/sign-in, and then you left that employment and lost control of the email account.

    But even then, the same core presumption means that the control of the email dictates control of the account. A person should let us know to update the email address.

    Once we've auth'd someone against Persona, then we know that the person owns a given email account. I can't see why this wouldn't then be used as the basis of trust to sign a person in, given that ownership of email is ownership of an account.

About

Avatar for Velocio @Velocio started