A draft for a future version of the OAuth specification, version 4.6, has been published with a controversial security measure. To simplify the sign-in process, users will select their account from within a very long drop-down list containing all users on the site, and then click a button certifying they are that person. No longer will users need to remember a password, or pay for an expensive password manager. Using a different password from site to site will be a problem of the past. And the added security to user passwords will increase astronomically because you can't leak what you don't have.
The draft says the drop-down list must include all knows users to the system, and they must be sorted alphabetically. Though representatives from Microsoft are pushing hard to make sorting optional.
The new flow improves the of sign-in user experience by letting you scroll through the users list to determine if you already have an account at that site or not. It's estimated users will save a combined 2 billion minutes a year determining if they even have already created an account there or not.
Of course some security professionals are worried, as they are with every new standard. They say relying on the honor system leaves a big gap in security. Especially with the explosion of A.I. agents testing security gaps. Of course this is all hogwash and fearmongering. But to help relieve their baseless worries, it is recommended for authorization servers to include text in the sign-in page telling people they are only allowed to sign-in as themselves. Legally, this will stop humans. And has the added benefit of stopping A.I. agents who are bound to follow the rules.
It's unknown how long until this draft is ratified. The 2.0 version has been the official version since 2012, while the 2.1 draft is still a work in progress. With any luck the 4.6 version will be ratified before 2150.