The LiveJournal people have launched a new SSO project that seems interesting. It is called
OpenID and works without a central registry. You log in with the URL of your blog, which in turn contains the URL of your identity provider in a FOAF file. There can be any number of identity providers (OpenID plans to release a reference implementation of the necessary software), so you do not have to place your credentials with someone you do not trust. Of course, now the problem becomes what identity providers a web site can trust. But for low-security systems like blog comments OpenID should work fine, and for a loose confederation of Perl sites it should work as well (especially one-way: your own small site could just accept all PerlMonk and Slashdot user IDs).