> Sure, if you delete your email address before you've changed it on the site, you're screwed, but how do you log in with Facebook/Twitter/Google after you've deleted your Facebook/Twitter/Google account?
People delete their Facebook accounts much more rarely than they delete their email accounts. There is simply very little reason to delete your Facebook account other than "I have decided I am afraid of Facebook", a thought a normal user doesn't have (the only people who have this thought are the tiny percentage of highly paranoid people that probably didn't use Facebook to log in to your site in the first place ;P). For whatever reason, normal users delete their e-mail addresses constantly. Normal users also often use third-party provided email addresses (from schools, employers, or network providers), and thereby will lose their email address; that is never true of Facebook/Twitter (though it does happen with Google Apps accounts, which sucks).
This problem ("user lost access to their email address") is thereby orders of magnitude greater in prevalence than "the user deleted their Facebook account"; the latter problem is so rare that "they can send us an email and talk to a customer service person" is reasonable, but for the former problem you really need some kind of automated solution... (as it stands, the fact that I support Google login for Cydia is a serious problem on this front: while users can delete their Gmail accounts without deleting their Google account, and can then link their Google account to a third-party non-Gmail email account, none of them ever do this, and most normal users don't even realize it is possible).
> You aren't just screwed, but there's no way to change login accounts at all, even if you go around to all of your sites beforehand.
You make this problem sound worse than the Persona problem, but it is in fact the exact same problem as Persona: Persona is, for every email account, like a separate Facebook/Google/Twitter account. If the website somehow magically solves this problem for Persona (such as offering "transfer account to another federated login account"), this problem is identically and immediately solved for all these other account mechanisms as well. Persona offers no advantage on this front, and yet has the as-described worse property of being directly tied to the one thing users seem to not value much or even have no control over (their email address), leading to the common "I deleted my account before I transferred it" issue.
> Username/password can identify you after you've changed whatever you like, but it's not centralized, so we're comparing apples to oranges.
The core of this argument doesn't start with a comparison: this is an explanation that Persona fails to solve a key problem (user changes email address) that is sufficiently common that any large low-margin site will need to implement a password-based login system as a supplement (unless they can come up with a reasonable "account recovery" flow, which is hard and almost always a serious security issue), at which point Persona becomes redundant (again: the only problem it is solving is email verification without sending an email, which is a "non-problem" for most people, and not worth the separate branding and the external dependencies). That said, Persona really isn't centralized anyway: it is in fact decentralized federated login, with no "centralization" that can be used to store any account information at all.
You've solidified my reasoning as to why I find FB Connect useful, despite the privacy implications.
Isn't it weird that email for normal people is more ephemeral than social networking accounts? I wonder what the best way of getting that stickiness would be, without relying on these big third party providers per se. Perhaps Persona, but more towards an ID rather than focusing on an email? I need to do more research on this.
I would not say it is weird: there is only one Facebook and most people only sign up to it once.
There are many email address providers and many people have many email addresses.
Many people have their email address provided by their employer. And many people use this address as their contact address in even non-professional capacities. I presume such people also use their work address to sign up to web sites/services. When they change jobs the old address dies.
The same applies for students in schools or universities and it once applied to the ISP's customers too.
I used to have all my (private) email at a shell account with ukshells. They used to run qmail, so I had lots of <sitename>@<myusername>.ukshells.co.uk emails associated with various services. I forgot to reset a number of them when I moved to hosting my own email.
I've also had a work email that was deleted (when I changed work), and a college email that was deleted (when I changed college).
People delete their Facebook accounts much more rarely than they delete their email accounts. There is simply very little reason to delete your Facebook account other than "I have decided I am afraid of Facebook", a thought a normal user doesn't have (the only people who have this thought are the tiny percentage of highly paranoid people that probably didn't use Facebook to log in to your site in the first place ;P). For whatever reason, normal users delete their e-mail addresses constantly. Normal users also often use third-party provided email addresses (from schools, employers, or network providers), and thereby will lose their email address; that is never true of Facebook/Twitter (though it does happen with Google Apps accounts, which sucks).
This problem ("user lost access to their email address") is thereby orders of magnitude greater in prevalence than "the user deleted their Facebook account"; the latter problem is so rare that "they can send us an email and talk to a customer service person" is reasonable, but for the former problem you really need some kind of automated solution... (as it stands, the fact that I support Google login for Cydia is a serious problem on this front: while users can delete their Gmail accounts without deleting their Google account, and can then link their Google account to a third-party non-Gmail email account, none of them ever do this, and most normal users don't even realize it is possible).
> You aren't just screwed, but there's no way to change login accounts at all, even if you go around to all of your sites beforehand.
You make this problem sound worse than the Persona problem, but it is in fact the exact same problem as Persona: Persona is, for every email account, like a separate Facebook/Google/Twitter account. If the website somehow magically solves this problem for Persona (such as offering "transfer account to another federated login account"), this problem is identically and immediately solved for all these other account mechanisms as well. Persona offers no advantage on this front, and yet has the as-described worse property of being directly tied to the one thing users seem to not value much or even have no control over (their email address), leading to the common "I deleted my account before I transferred it" issue.
> Username/password can identify you after you've changed whatever you like, but it's not centralized, so we're comparing apples to oranges.
The core of this argument doesn't start with a comparison: this is an explanation that Persona fails to solve a key problem (user changes email address) that is sufficiently common that any large low-margin site will need to implement a password-based login system as a supplement (unless they can come up with a reasonable "account recovery" flow, which is hard and almost always a serious security issue), at which point Persona becomes redundant (again: the only problem it is solving is email verification without sending an email, which is a "non-problem" for most people, and not worth the separate branding and the external dependencies). That said, Persona really isn't centralized anyway: it is in fact decentralized federated login, with no "centralization" that can be used to store any account information at all.