Let's not forget that for a vast amount of people, this just means remembering a single username+password.
Even just for login, though: Persona doesn't solve this problem as well as Facebook Connect (from either the perspective of the site administrator or the user) as it assumes email addresses are canonical and unchanging, which is not true for normal users (who tend to change email addresses occasionally to get rid of spam or old contacts they no longer like; they also often get their email addresses only temporarily from schools, employers, and network providers). Please understand: I have had the same email address since the late 90s, and likely most people reading HN care about canonical identifiers, realize the security issues involved with losing their email accounts, and often have business reasons to not lose access to old contacts--we are not "normal people".
With Facebook Connect the user normally cares more about their account (people change Facebook accounts much less often than email addresses), and when their email address changes they can update it on Facebook without bothering the site they are using. (I run a site that uses only external login providers, either Facebook or Google, and the users who log in using Google often contact me saying they changed their email address and now can't log in to my site anymore as they had to make a new Google account. I frankly only offer Google because some people hate the very idea of Facebook.)
This undermines one of the major advantages of using third-party authentication providers. For site administrators, it means you still need some way to identify and authorize accounts separate from Persona (so as to know the user contacting you, who no longer had access to their old email address, is really the user they claim to be), and for the user it means they still have to find all the websites they have previously logged into in order to correct their email address, and they must do so manually and painfully (potentially talking to a customer support representative).
If all Persona did was "email verification" that might actually be kind of awesome, and then have that tied to an existing login system (maybe one involving a username and a password) provided by the site (or even by a third-party), but it ends up being sufficiently intrusive to the flow that it just doesn't feel right to use it and another login mechanism, which means that these killer "email changed, don't have access to old e-mail address" issues become entrenched. That also isn't how Persona was marketing itself, so no one seems to think to use it that way (leading to the "it doesn't seem to better solve a problem I really have" issue).
(I have written more about this subject in the past, with at least a small amount more detail on some of the other problems that can arise with relation to email accounts provided for temporary use, such as by the aforementioned schools, employers, and network providers; the short version, though, is that email addresses often get reassigned, which makes the entire idea of using an email address as the basis of what is supposed to be a widespread secure login mechanism insane. OpenID has tons of its own adoption issues, but at least it required providers to never reuse their identifiers between different people, and provided a simple way to allow that to be possible... I mean, even Yahoo and Hotmail expire and recycle accounts, so this is a serious problem.)
The easy solutions I can come up with to this problem negate all the benefits of Persona past "email verification without sending an email", which is a non-problem for most people, and not how Persona is marketing itself (in particular, you can't rely on it as a login provider: you need a password or something instead). It is ludicrously irritating to have to deal with these issues manually; at least Google (which also causes this problem) offers other benefits (names, genders, profile pictures, and with G+ a list of friends to easily add social features). The other options you have are ludicrous "account recovery" flows, such as Facebook's "get five of your most trusted friends to vouch for you" mechanism, which shouldn't be needed for this all-too-common case.
Persona is better than the other centralized login systems in this respect, and is second only to username/password. Username/password can identify you after you've changed whatever you like, but it's not centralized, so we're comparing apples to oranges.
People delete their Facebook accounts much more rarely than they delete their email accounts. There is simply very little reason to delete your Facebook account other than "I have decided I am afraid of Facebook", a thought a normal user doesn't have (the only people who have this thought are the tiny percentage of highly paranoid people that probably didn't use Facebook to log in to your site in the first place ;P). For whatever reason, normal users delete their e-mail addresses constantly. Normal users also often use third-party provided email addresses (from schools, employers, or network providers), and thereby will lose their email address; that is never true of Facebook/Twitter (though it does happen with Google Apps accounts, which sucks).
This problem ("user lost access to their email address") is thereby orders of magnitude greater in prevalence than "the user deleted their Facebook account"; the latter problem is so rare that "they can send us an email and talk to a customer service person" is reasonable, but for the former problem you really need some kind of automated solution... (as it stands, the fact that I support Google login for Cydia is a serious problem on this front: while users can delete their Gmail accounts without deleting their Google account, and can then link their Google account to a third-party non-Gmail email account, none of them ever do this, and most normal users don't even realize it is possible).
> You aren't just screwed, but there's no way to change login accounts at all, even if you go around to all of your sites beforehand.
You make this problem sound worse than the Persona problem, but it is in fact the exact same problem as Persona: Persona is, for every email account, like a separate Facebook/Google/Twitter account. If the website somehow magically solves this problem for Persona (such as offering "transfer account to another federated login account"), this problem is identically and immediately solved for all these other account mechanisms as well. Persona offers no advantage on this front, and yet has the as-described worse property of being directly tied to the one thing users seem to not value much or even have no control over (their email address), leading to the common "I deleted my account before I transferred it" issue.
> Username/password can identify you after you've changed whatever you like, but it's not centralized, so we're comparing apples to oranges.
The core of this argument doesn't start with a comparison: this is an explanation that Persona fails to solve a key problem (user changes email address) that is sufficiently common that any large low-margin site will need to implement a password-based login system as a supplement (unless they can come up with a reasonable "account recovery" flow, which is hard and almost always a serious security issue), at which point Persona becomes redundant (again: the only problem it is solving is email verification without sending an email, which is a "non-problem" for most people, and not worth the separate branding and the external dependencies). That said, Persona really isn't centralized anyway: it is in fact decentralized federated login, with no "centralization" that can be used to store any account information at all.
Isn't it weird that email for normal people is more ephemeral than social networking accounts? I wonder what the best way of getting that stickiness would be, without relying on these big third party providers per se. Perhaps Persona, but more towards an ID rather than focusing on an email? I need to do more research on this.
I've also had a work email that was deleted (when I changed work), and a college email that was deleted (when I changed college).
There are many email address providers and many people have many email addresses.
Many people have their email address provided by their employer. And many people use this address as their contact address in even non-professional capacities. I presume such people also use their work address to sign up to web sites/services. When they change jobs the old address dies.
The same applies for students in schools or universities and it once applied to the ISP's customers too.
Is the name of the site a secret? How many sites have this many users (I understand you talk about registered users, since we're talking profiles/login issues here)?