Earlier quoted context omitted.
http://en.wikipedia.org/wiki/Federated_identity
Federated identity doesn't replace passwords, it just punts the whole process of authentication to a third party. That third party will still need to authenticate the user somehow, which brings us right back where we started.
It'd be nice if everyone who runs a non-trivial website stayed was a security expert, but we're also busy with other aspects of the site.