> Technically correct, but it makes it a lot easier at a practical level, especially for non-technical users.
So, let them put their unencrypted keys on, err, Firefox Sync or Dropbox or whatever, and not give a damn. It would be almost exactly the same security level - identity conveniently secured by an external service.
I just don't see a downside. Yes, the keypairs don't have a human-readable name - but they don't have to, they're just like passwords, except for they can be globally recognized (if user wants to). Yes, for non-paranoid users' convenience we need some sort of key escrow system with some trusted party that can take hold of a file - but that's well possible and I think every other user has some "cloud storage" those days.
> This is not a requirement of Persona.
Yes, you're right. I simplified it a bit. A requirement of Persona is that IdP is a very specific service identified by a domain name, not an email. But the rest of logic should still hold.
> How do I as an application provider trust your assertion?
Generally, you don't need to check assertions, unless you want to confirm that this specific user has some affiliation with this specific third party. Then you check a signature from that party.
If you don't need an information that your user is also a specific person on, say, Facebook, or, say, a representative of some company (verified by a notary) - you don't need to care about any assertions. You just take a key and that's it.
Seriously, an average service does not need any identity assertions. Do you need a passport to enter a restaurant or a store? It's the same thing here. (Ok, maybe you do if that's a gun or liquor store, or some private lounge that needs a membership.) Oh, and, sure thing, almost every store out there would just love to ask for a passport and have a very detailed and extensive tracking of their visitors.
> At bare face value an "identity asserted by a keypair" is a fingerprint, a boring hexadecimal hash. I don't know very many people that associate themselves as "fe:02:aa:45:c3:d0".
Neither do I, but I don't see why you thought about using fingerprints as identifiers for humans. Those are credentials, not identities, although they're tied because it's hard to separate the concepts. Users already have a lot of weird stuff but and don't care that they're username/pbkdf2_sha256$12000$6Q0D5rq4nz1m$xsAqY1hlIuFqY4sD+9Ia0dxNLooy+jmHFJCrBgByhHw=. Let us leave those details to computers. Hope you see the idea.