Does the Apple keychain handle certificates? Because I thought we'd all moved on from remembering two or three passwords to letting software manage and synchronize those. It's been working flawlessly for a couple years now. Although at that point, a long, unique password seems to be about the same as a certificate.
Anywhere also means from any device, not just ones you own and have set up with your iCloud account. Mind you, I'm not saying that it's a good idea, logging into anything from anywhere willy nilly.
True – I can look up passwords on my phone. But copying a certificate may be slightly more annoying.
Everyone could have their own certificate authority on their person in a small usb device. You could even generate one time login creds if you were on a public machine.
Which is great as long as every machine you log in from permits USB devices.
and is positioned in a way that frequent use of the USB ports was convenient. I'm thinking of 2 places I visit frequently where the computers are hidden under a big ol' desk
And as long as you don't lose the USB drive, or sit on it wrongly, or otherwise make it unusable.
The best and most durable solution is really some RFID tags embedded in your wrists and forehead.
Haven't you just described 2FA?
So why not just current 2FA instead of certs?
With 2FA I have my password and pull out my phone to look up a code. So I still only need to populate one device.
No, with 2FA, I need my password, and my phone. I only have to set up one device: my phone (or whatever other 2FA token). I don't have to go through my home computer, my laptop, my phone, my work computer, my friend's computer, etc. and set up my certificate everywhere just because I might need to log in to a website.