AT&T and Verizon want to manage your identity across websites and apps
arstechnica.com
arstechnica.com
I'd much rather authenticate to websites with a key stored in my phone's secure element than I would with an auth service provided by my carrier.
I don't know for sure why they decided to do something new rather than improving the UX of client certs, but what they came up with for Webauthn seems to work with pretty well.
"Four companies that nobody trusts want to manage your identity across websites and apps."
Seriously from the T mobile data breaches affecting millions[1], to Verizon's injecting of X-UIDH headers[2], to AT&Ts work with the NSA[3] to the selling of location data by all four mentioned in the article, there is absolutely nothing trusty-worth about any of these companies. It's like cognitive dissonance. Maybe they could include credit monitoring by the 3 completely untrustworthy credit reporting agencies and the service would be feature complete in its' absurdity.
[1] https://www.usatoday.com/story/tech/2015/10/01/t-mobile-brea...
[2] https://www.eff.org/deeplinks/2014/11/verizon-x-uidh
[3] https://theintercept.com/2018/06/25/att-internet-nsa-spy-hub...
https://www.cnet.com/news/t-mobiles-transparency-report-reve...
At any rate the bar seems pretty low in that group.