When your browser and email provider both support BrowserID:
1. You log into e.g. gmail.
2. Your browser generates a keypair and sends the public key to gmail.
3. Gmail signs your public key and sends your browser a certificate saying "this key is owned by whoever@gmail.com".
4. You click "sign in" on some site (e.g. Hacker News) that uses BrowserID.
5. Your browser sends Hacker News an message saying "my user is whoever@gmail.com", that is signed with the private key generated in step 2.
6. Hacker News looks at the "gmail.com", grabs gmail's public key (the one that signed your public key in step 3) and verifies the signatures.
Hacker News now knows that you control whoever@gmail.com.
The process is described fairly well (diagrams and everything) at http://lloyd.io/how-browserid-works