It’s long been my feeling that this is the way online identity ought to work: requiring a single site for sign-on (even one as big as Facebook) creates a single point of failure that is un-webby. By making it a protocol understood by browsers, you make it distributed, and by making the UI part of the browser chrome rather than a web page, you make it much harder to create phishing sites. It’s pretty useless until all browsers support it, but I hope they will. Keep an eye on this project.