There are already Gmail/Microsoft/Facebook providing single sign on for users.
That doesn't mean applications are bothering to support them.
Actually, Facebook is ubiquitous for popular apps to the point it's often mandatory. (too bad for privacy :( )
Google App for business (and Microsoft to a less extent) have market shares among professionals but many SaaS and hosted applications cannot integrate with it at all.
Good points. I'm not proposing a single owner, but rather a federated protocol where sign-in operates over email with each person's mailbox provider. The hope is that each mailbox provider will provide the sign-in.
- whatever solution we come up with needs enough market force to push adoption
- whoever gets to own "single sign on" owns the world. This is why there was so much backlash against Microsoft Passport all those years ago.
Personally I'd favour some sort of hardware token, and we're very slowly moving in that direction with U2F.