>
It always pained me greatly that every rinky-dink website on the entire internet demanded that I create a special username and password just for them. ... For the vast, silent majority of normals, who know nothing of security but desire convenience above all, this means one thing: using the same username and password over and over. And it's probably a simple password, too.> This is the status quo of identity on the internet. It is deeply and fundamentally broken.
What I do is, I have a couple of hard passwords that I use for email and Dropbox and important services like that, and then I have a couple of stupid usernames and passwords that I use and re-use and re-use for services whose security I don't care about. (I've arrived at this strategy after years of using the internet.)
A couple of times, I have actually tried to register an account with my usual username, found that the name was taken, wondered "Hmm, did I already create that account?", tried logging in with the usual password, and found that the login worked. "Oh, yeah, now I remember making that account..." I took this as a good sign, that I wasn't wasting brainspace on that login.
I think my strategy works fine for dealing with "a dozen websites who all want a username and password", given that only one or two of them are critical. And therefore I'd question the need to change, as opposed to people figuring out a strategy like mine and passing on the idea. Also, currently, anonymous throwaway accounts are easy to create; would it be that way if sites required something like OpenID? (I guess if the idea is just to reduce password complexity for customers, then sites could just add OpenID as a secondary means of logging in--rather than having it be the sole means--and you could still make throwaway accounts. Note that I don't know anything about OpenID; maybe there is a way to do anonymous throwaways within OpenID.)