The terrible, terrible UI.
Plus: the same problem as normal SSL certs: the registries aren't secure/trustable.
Plus: the same problem as normal SSL certs: the registries aren't secure/trustable.
I believe in design in depth, and by allowing the most basic of techniques (form submission + cli tool stack) to handle something that is generally perceived as difficult and letting people "get" the manual process, the automation might not seem as daunting.
I did not intend to create a standard, just to provoke more discussion. I would however by gladly surprised if I woke up tomorrow and twitter allowed me to sign in by solving a challenge instead of a password : ).