While this is very impressive, it feels like trying to solve the wrong problem. The real problem is getting rid of passwords (Persona, anyone?).
Don't get me wrong, what's described there is super-important to secure the authentication of today, but what about a word for the authentication of tomorrow?
There already are various solutions. Passwordless[0] is a familiar one for nodejs, and I recently bumped into the promising Portier[1], which is, according to its authors, a "spiritual successor to Mozilla Persona".
For most companies offloading your password management onto an email provider is the right way to go. Suddenly, for free, you get MFA, a dedicated security team, and you'll never need to do one of those "Our password database has been hacked. Here's what we're doing..." press releases.
You've eliminated one point of failure (your company), and haven't added any because you are already doing email based password resets.
You can delete all your password related stories from trello or whatever.
You eliminate all the bike shedding around how to store passwords.
You've improved your initial user experience by an order of magnitude. Everyone dreads setting up yet another account password. Don't underestimate the joy a user feels when the signup form is just "click one of these buttons or fill in the email field". (The buttons are 'Connect with Facebook' and 'Connect with Twitter').
Users would much rather flip over to email (which is always logged in anyway) and click a link (especially on a mobile device) than enter a login/password.
That doesn't have to be as annoying as it sounds. If you use Gmail for example you can login via Google Sign-In, and later a system like that can support generic OpenID. Also, once logged in the site you logged into can save your session – it's not like you log into pages every time you use them.
It kind of moves the problem, yes – instead of securing password on each and every site you only have to protect your email password. But that you do have to do already, so imho it only removed one problem.
If this were implemented and my email account (which still uses a password) was compromised, wouldn't said attacker then have access to all my accounts using this method?
Don't get me wrong, what's described there is super-important to secure the authentication of today, but what about a word for the authentication of tomorrow?
There already are various solutions. Passwordless[0] is a familiar one for nodejs, and I recently bumped into the promising Portier[1], which is, according to its authors, a "spiritual successor to Mozilla Persona".
[0] https://passwordless.net/
[1] https://portier.github.io/