Agree on all points. But I still like the idea as an optional way for people to log quickly in without having to give the site owner any password info.
And yeah its a little more tedious if the site doesn't have a long session time.
Depending on the security needed for a particular application I have been wondering why not just Email for authentication since its common for password recovery. More here: http://blog.headspin.com/?p=352
And yeah its a little more tedious if the site doesn't have a long session time.