To be accurate, partner Shell choose not to re-up its investment after exactly one year, from 2019 Feb 12 to 2020 Feb 18 as indicated in the blog post you linked (actually https://link.medium.com/KBxNNZGcK9 since your link didn’t work for me). It seems unfair to blame Alphabet solely, or even Larry, as one comment below did.
To mention only Wirecard misses a wider scandal and the “massive hack-for-hire“ India-based operation BellTrox with hundreds of clients, as documented by CitizenLab.
Cell phone companies have to port numbers between carriers, I wonder why Google can't do it? I would be all over this if I could keep my cell phone number...
I suspect like Skype they are being careful not to claim they are a telco - so they don't get hit with all the regulation and requirements stuff that real phone companies have. At the moment they are treated like those companies that sell cheap international calling cards.
“Simple browsers” (#2), i think, has already been solved. Take http://Shiira.jp/en.php or Safari on the iPhone. The larger problem is how to make mass audiences aware without mass advertising, or to make it affordable to those without income. Seeing this problem under the lens of getting computer and media illiterates to open their minds, or employing the permanently unemployed, better reframes the challenge.
As we know, hackers regularly turn random door knobs to see which doors open. Logs i can see show more black hat attempts than white hat, so either OldGregg's friend got lucky or a few exploits might have already been made.
The weakness of the above argument: Why would site-owners install an untrusted Clickpass widget spread around the net but not from Clickpass itself?
I can see how some users might fail to recognize a Clickpass or OpenID url and give their login credentials to a fraudulent site, but no worse than password management, OpenID requires folks be on guard against phishing.
In the cat and mouse game between site owners and spammers, data on recent Ma.gnolia registrations showed an overwhelming number of spammers have begun using automated tools to proxy Captcha and create traditional address and password logins. For now, OpenID encumbers them by requiring presumably more valuable credentials.
As a website owner, OpenID nets your site security. Most people reuse the same small set of usernames and passwords. A not-so-small number of sites store cleartext passwords; they can even mail it back to you. Regardless how well you execute security, a breach at any of these sites compromises security across many user accounts across many sites.
Several weeks ago a Web 2.0 company launched a Gmail backup app that asked for addresses and passwords, which at least 1777 unwitting folks provided. In addition to backing up Gmail as expected, the app also socked away the address and password combo. When the scheme was exposed, the company said debugging code inadvertently made it to production. http://codinghorror.com/blog/archives/001072.html
I can see scenarios where the government may be the least of our worries. Much more likely are significant others' jealous exes who are also system administrators, and other real or potential enemies. The sooner we move away from passwords and other shared-secret systems, the safer we'll be.
America Online + AIM, Yahoo, Flickr, Livejournal, Vox, Typepad/key, Google, and enough widely-used sites, plus Drupal, Wordpress, and other widely-used platforms provide OpenID that very few users would need to create yet another login/password. Those already with many logins would likely already have multiple identity providers from which to choose. Those with few logins would presumably have less of an issue.