That RSA handshake saying "hey, it's me-- check the Web of Trust & the fingerprint of this public key I gave to you in person")/identity verification(there's a reason why you not only encrypt but sign your data with PGP) is especially now important to run on your own server & effectively trivialto set up with Docker (which I'd bet at least 70 percent of the readers here use.) To add SSO support for SAML2 (or JWT, or whatever you want-- passport.js supports it all) so others can use their own IdP's to authenticate in via WS-Federation is now trivial.
One day there's going to be some catastrophic data leak of the magnitude of the Philippines leak, of the social importance of the Panama Papers, and of the shock value of the Ashley Madison leak and we'll only have ourselves to blame for making our fun toy web-apps auth against only FB and Google.
[1] This has been a "solved" (mathematically + progmatically via PGP 2.0 for ~25 years with Zimmerman's implementation of the Web of Trust). Who remembers key-signing parties?! Haha. If you lose your key, you call up your buddy Bob who has an authentication claim with the sole ability to talk to the Identification Provider, Alice (whom you and Bob both trust to run your SSO) and your certificate is immediately revoked, so even if your private key and passphrase and device are all lost, no new data the second your key's state moves to 'compromised'. Alice can pull the plug on her RasPi's IdP, killing the whole and I might sound like a tin-foil hatter but re-decentralization for the internet has never been more important. She can pull the plug on it or have a cron-dead-mans-switch that discharges ESD to the volatile RAMdisk and kills the power, at worst she'll get an obstruction of justice charge. Multi-national corporations will comply court-orders if their in-house counsel says the demand isn't viably disputable.
The internet was rooted in academic/sharing culture, and ARPAnet was designed with decentralization as such a fundamental component that redundancies were put in place to literally route information successfully with a significant part of the nation offline as a result of nuclear war. Walled gardens like this are inherently vulnerable to government intervention. That Israeli firm compromised (as I understand it) the iPhone in the 'pwned' sense. If this is a reaction to the public distrust of iPhone as a platform, this isn't any more secure than before. Apple still has to have the initialization vector/nonce/whatever that's seeding the pseudo-random number generator.
From the BSD[2] culture we came, to there we must return.
-- [2] More so referring to the culture of EDA semi-conductor tooling & the attitude of "here, take it, use it, and enhance it, and release it back into public domain, more so than the whole BSD 'the SysV UNIX competitor' and all of the derivatives were spawned from it).
See: https://en.wikipedia.org/wiki/VLSI_Project, https://www.mosis.com/products/fab-processes (which yielded SPARC), http://wiki.geda-project.org/, etc. IBM was also was the other instrumental player in the 70s/80s to enable chip-houses to get past that proverbial wall of a few hundred k components on an IC. Rumors around the EE scene has it that low-run-custom-SoC's are the next B2B move chip houses are going to push, but we'd still be on System/36s and VAXstations if if it weren't for some associate professor in his 30s and a few 25 year old PhD candidates who pushed out the chiptooling that's still in use today (MAGIC, SPICE, and all the subsequent derivatives).