Something low friction, like Sign in with google/Facebook/github whatever, where somebody else manages your identity for you, is going to be much lower friction.
I suppose it's a tradeoff. I can accept the small risk of a huge inconvenience (if my Google account were shut down) in exchange for the daily usefulness of Gcal, mail, docs, etc. I wish they'd just move to a paid plan.
It was in that moment that I decided the risk was unacceptable and that I’d switch to my own domain for all emails. It’d just be so devastating losing access to my email.
I'd certainly like to log in with my yubikey
I think, for the general non-IT crowd, exposing them to those systems is likely to cause more harm than good. Even most dev types struggle with using git effectively...
At some level you start requiring certificate authorities (central trust). The DID-core W3C proposal seems to be putting down some of the pieces required to enable rolling your own identity authority. But it is still a long way to go even after around 4+ years.
The issue is if you are emailing a counterparty with whom you have no trust established yet, there is no way for them to trust your public key (or for you to trust their public key) unless you have somehow exchanged keys in a secure manner. This is the key distribution problem.
Certificate authorities help manage this by notarizing your public key with theirs and if the CA is trusted by the counterparty, they can use it to validate the public key is from you.
Having said that, it would be great if mobile operating systems had services that could support key notarization and if you could configure say 4-5 of your trusted contacts to act as notaries and they vouch for your public key automatically. With DID-core, this may become possible.