XAuth is a lot like democracy: The worst form of user identity prefs, except for all those others that have been tried (apologies to Churchill). I've just read Eran's rather overblown "XAuth - a Terrible, Horrible, No Good, Very Bad Idea", and I see that the same objections are being tossed around; I'm going to rebut them here to save time in the future. Let's take this from the top. XAuth is a