The problem with using email for login is that it breaks the promise that you can trust the Web because you don't need to trust websites. The second you log in, you've handed over a tracking and spamming vector. Architecturally, it's not great.
Some notes gist.github.com/darobin/77868e…