Also, a common problem with all browser-based authentication systems seems to be what happens when the user loses the browser. (Hard drive failure, theft, etc.)
With LastPass, I can retrieve my passwords by reinstalling the add-on and entering my master password, because all the data is kept on their servers. With browser-based authentication schemes without a central server, once you lose your browser, it's gone. It's also virtually impossible to remember a randomly generated private key, unlike even a 10-word passphrase. So I'll only ever be able to use this with unimportant sites, not e-mail or banking. I see that this problem is mentioned in the "technical limitations" section, but any good idea to fix this without asking users to trust a central server?