How BrowserID differs from OpenID
identity.mozilla.com
identity.mozilla.com
If only people owned their email addresses then this would be a truly decentralized (eventually) and portable identity system. I do think emails are the best global handle for users that we have currently - we should treat it as such.
The web needs this to be widely adopted. They've got some unique challenges to make it easy to integrate and easy to understand but I think they're on the right track.
At least with email, provided by the email host, the string you get from them will be unique.
Having the browser handle the authentication makes for a much more seamless experience.
If NAT and firewalls weren't such PITA, browser could even act as an OpenID provider for itself (e.g. Opera Unite makes it possible).
The problem with OpenID is lack of discovery. AFAIK there is no way to advertise that website supports OpenID login and where it should be submitted, so browsers are unable to have integrated UI for it.
Why would different auth methods in browsers cause problems, when different provider's methods don't?
AFAIK client auth method is invisible and irrelevant, especially in the case where client and provider are the same thing (the browser).
In fact, in-browser OpenID (where browser is the provider) could skip client authentication completely and just say "yes" to every consumer (because browser knows and trusts its own identity).
Public-key crypto may be easy to understand and secure, but until now it's not had good browser integration, it's been hard for websites to manage, and there's been no adoption.
(For example, if you write your own public-key auth mechanism for a website, you need to program all the backup mechanisms in case the user loses their key due to browser failure, needs to recover their account because of a security problem, or whatever. BrowserID outsources that to email providers or secondary authorities.)
Check out the detailed protocol explanation:
https://wiki.mozilla.org/Labs/Identity/VerifiedEmailProtocol
With all the free email options available I doubt this would be a serious problem. I also know some sites are requiring unique email addresses in their DB now. I simply wonder how many users still do this and if it would negatively impact them.
Why would I want to use my email address as an identity? I already get more than enough spam.
This assumes that foobar webapp accepts + as a valid email local part character which is not always the case unfortunately (and against RFC) but that is another story.
Just sayin
e.g. first.last@gmail.com is the same as firstlast@gmail.com
For stubborn services who don't accept "+" in email addresses use unique redirect aliases.
(Also, IIRC, Gmail ignores dots, i.e. "j.random.user@gmail.com" and "j.r.a.n.d.o.m.u.s.e.r@gmail.com" is the same address. Chose a canonical one with a dot somewhere, and filter the rest with exception for legimate senders.)
BrowserID breaks this.
I guess it can't be 100% automated, but you don't want automated logins anyway.