Before I start, let me make myself very clear - I think Dan did an awesome job with Foamicate. Seriously. One guy. The balls to put something out there that's innovative and seeks to solve a REAL problem. I'm impressed. And if I were in a position to, I'd ask Dan to work for me.
That said, it's worth (IMO) considering what an identity system should provide -
User Control and Consent: An identity system should only reveal information identifying a user with the user's consent. The Facebook/Google/OpenId model fails this one.
Minimal Disclosure for a Constrained Use: The solution that discloses the least amount of identifying information and best limits its use is the most stable long-term solution. Again, OpenId falls short in that the identity provider knows where the user is going.
Justifiable Parties: Digital identity systems must be designed so the disclosure of identifying information is limited to parties having a necessary and justifiable place in a given identity relationship. Microsoft Passport is a great example of why this's a bad idea.
Directed Identity: A universal identity system must support both "omni-directional" identifiers for use by public entities and "unidirectional" identifiers for use by private entities, thus facilitating discovery while preventing unnecessary release of correlation handles. My Facebook identity is public, but I can't and shouldn't use that to access a private resource like a collaboration site on my company's extranet.
Pluralism of Operators and Technologies: A universal identity system must channel and enable the inter-working of multiple identity technologies run by multiple identity providers. The part where anything that's exclusively browser-based fails. The same system should work online, from a phone, and from a PC or server running any arbitrary OS.
Human Integration: The universal identity metasystem must define the human user to be a component of the distributed system integrated through unambiguous human-machine communication mechanisms offering protection against identity attacks. UX. The usability problems with Foamicator have been discussed here already.
Consistent Experience Across Contexts: The unifying identity metasystem must guarantee its users a simple, consistent experience while enabling separation of contexts through multiple operators and technologies. A smart card is a good example of this - I have a card for cash, a loyalty card for coffee, and an access card for work. Using them is consistent, event though their context is not.
The only technology I know of that meets all 7 laws is information cards (Higgins Project, and CardSpace). Information cards haven't taken off because adotpion by identity providers is, well, basically zero.
Which is a shame.
Anyway, if you're interested in this you can find more information at http://www.identityblog.com/.