After reading the protocol spec, I have a somewhat better understanding of this. If I got this right, this is basically what this does:
* asymmetric crypto authentication in the backend.
* control over email address == authentication.
* allows a trusted third-party to authenticate the user. This could be a user or a web service (like browserid.org?).
* falls back to regular email authentication we see every day.
I'm still unclear how you can securely verify email ownership thru cryptographic means. Anybody care to explain it?