> It seems inevitable in a web of trust that fraud rings would emerge to manufacture identities for those looking to escape debts, criminal convictions, etc by some combination of tricking and bribing people to sign authentications.
Which could possibly be counteracted by attaching a certain amount of liability to a signature? Also, you potentially can detect fraud rings. But, as I said: I am not really proposing anything.
> I'm not sure you should be able to use, say, a poorly written IE extension on your unpatched Windows XP machine.
Yes, you should, absolutely. Not only is it impossible to enforce anything else, but that's just your own responsibility, just as locking your own home or car or whatever is your own responsibility.
> Something federated would be great, where any manufacturer can technically make something compatible, but it has to meet a FIPS standard or something.
Federated? You mean an open standard? Yes, that would be the idea. But none of the FIPS crap, that never works. Certification only prevents improvements, security fixes and the like, and usually only guarantees a minimum level of security that's worse than what would happen without it.
> Keys could be generated onboard, and then you upload your public key or something.
No, keys are generated however the customer wants to generate them. The customer supplies a public key to the bank, and it's the customer's responsibility to keep the private key secure. If they think a smartcard from a specific vendor is the solution they trust, that's fine, more power to them. If someone else trusts more their own software on an airgapped raspberry pi, they should be able to do that.
> We're getting way ahead of ourselves - banks are extremely hesitant to use anything better than secret numbers. I'd rather a shitty 2FA implementation than that.
I don't. The more technically complicated the authentication system is, the harder it is to make people, and especially courts, understand what the failure modes are, and thus, who should be liable when something goes wrong. Lists of random numbers are relatively easy to understand (especially the fact that a bank obviously knows the "secret" numbers and thus cannot really prove that they got it from you).