What's needed right away is a "badge of security approval" from an independent third party, which verifies not just the technological side, but the customer-service side too. Including things like:
- password policies (e.g. not limiting to 16 characters)
- hashing and salting passwords
- standards for security questions (these are usually so horribly written)
- standards for identity verification if you've forgotten password AND sercurity question answers (most sites will not be big enough to bother with this, so you just lose your account, but Facebook/Apple/Google/etc. need to have a common model, so inconsistencies between companies can't be exploited)
- policies for sending out password-reset emails, adding/changing e-mail addresses, with appropriate user notification
- waiting periods between changing emails and passwords, so you can't just go and change everything about an account all at once
- special unique privileges to initiate operations that can delete large amounts of data (like a special second password, or extra security questions, for deleting your account, remote wipe, etc.)
These are just vague ideas off the top of my head, not an actual proposal. But we really need a set of "best practices", and a way of identifying that companies are actually following those best practices.
A secure "lock" icon in the browser bar is no longer enough.