Honestly curious, what should we use?
It was a complete nightmare unless you understood what public key crypto is, how it works, and how to configure your browser for it.
Don't get me started about having to move your certificate/keys around.
It doesn't work for the masses.
I don't know how feasible it would be to replace passwords for the general public, but if browser vendors were actually serious about security, they could go a very long way towards making client certs feasible just by giving up on their current strategy of putting their fingers in their ears and pretending it doesn't exist.