Identity is broken.
geekatsea.com
geekatsea.com
Oddly enough, I think it might be credit card companies who are in the best position to solve this problem. They already have a large infrastructure for detecting fraud, they have the trust of the general public, and they already have a high level of integration with many websites. More importantly, they have a business model that is not predicated on selling your data to make a profit (well, at least not entirely).
The problems are that not every site supports OpenID, and that owning/maintaining one's own domain isn't as easy as getting an email address (tough for grandmas to do). The former issue would solve itself if OpenID would become more used (kind of a paradox), while the latter is slowly gaining traction, I think (now with sites like GoDaddy it's not too hard for lay people to buy a domain and write HTML with a WYSIWYG editor). Remember, there was a time when getting an email address was not a trivial thing.
There's clearly a need for a standard login, but there's also a need for a much brighter line between identification and permissions. Until that happens, even when it's available, many users will shy away from using a standard login.
http://www.mozilla.org/en-US/persona/
This article actually somewhat validates the approach BrowserID takes: you use your email address as your ID. BrowserID provides a way to verify that you own the email address in question (that you are who you say you are).
There's a lot more planned, but the core of it is simple and easy to implement.
ObDisclaimer: I work for Mozilla, but not on Persona.