I wonder how well client-side SSL certificates could aid in this process. This way servers would only have the public key of a user and as long as the user doesn't compromise their private key they'd be safe.
They're certainly available -- at least, in Mozilla -- but usability is poor. The most obvious issue is that there's no obvious way to copy a client-side certificate to another machine, making it incredibly awkward for users who use multiple computers (or, worse, who only have access to shared computers).