A tiny dedicated computer like Tomu[0] that fits into your computer, that provides authentication (and similar cryptographic functionality), with inpedentent input (touch) to receive manual ACKs and output (led) to provide feedback, with no other functionality, is a cheap, reasonably safe, and convenient solution. Maybe unlock it on boot (and after timeout) with a password/PIN for good measure.
Currently I'm using Chrome backed by KWallet backed by PGP key on a YubiKey 4. Upon launching Chrome I have to authenticate with/touch the Yubikey to unlock my session, which is spiffy, but after that seemingly random pages (even in an incognito window) will prompt Chrome to unlock my keychain. The Yubikey will flash, indicating something wants access to it, but I have no indication of what that something is. If I ignore the flashing, eventually a KWallet window pops up complaining about being unable to use the GPG key.
Chrome shouldn't access your credentials without telling you what it's used for. Chrome shouldn't expose cryptographic identities in incognito mode. The Yubikey's output is vague.
What can we learn from that?
Chrome has shortcomings in this domain. Just one monochrome LED is maybe not enough output to give reasonable feedback.
My online banking security system is called chipTAN and uses a small, monochrome, low-res display to give essential information for what is being processed which I need to acknowledge. That works well, but is also a single-purpose solution.
For identification on the internet, a solution based on GPG seems reasonable. Imagine a small display that shows the receiver you are identifiying to, the identity you are using, and for how long the identification is valid, and then you can acknowledge that.
And even then, malware can still just steal your cookies.