The problem with every site handling their own logins is that you're creating more vectors for attack. Most people reuse passwords (bad practice I know but it is what most non-technical people do) and not all sites are properly secured - in fact some don't even encrypt passwords! So at least passport sites outsource the data protection issues to larger businesses that you'd expect (no; demand) to have experience to handle that data securely.