While using LOTW certificates is quite ingenious, I think the whole process to extract the keys will be a big hangup for the less technical folks.
It really needs to be as easy as possible, like how you can use you facebook login (oauth token) to log into other sites.
Basically it your ARRL login should work like that, so you can login to the ampr portal, qrz, etc.