Remember how Facebook was going to act as a single sign-on for everything you did on the Web? Remember how trusting you felt about that?
Well, now there's Project Verify. The four major US mobile carriers have banded together to become a single sign-on for everything you do on the Internet. No privacy issues there, right? After all, the carriers have never needed regulation about the data they collect on you, and they're completely transparent about what they do with it, right?
If it's not a physical token it is subject to MITM attacks. And then have all 4 carriers using the same AUTH system? Really? Some ISSO's aren't doing their job. 4 different sources should all be saying the same thing: "If one domino falls, they all go."