http://googleblog.blogspot.com/2011/02/advanced-sign-in-secu...
yet my bank's web site, not so much.
What I was talking about was something different. Public/private key encryption where only the public key is stored on the server.
Here's an example scenario: the server generates a random pass-phrase then encrypts it using the public key. The end-user then uses their smartphone where the private key is stored to decrypt the message and return the original pass-phrase back to the server, proving they have the private key. There are similar ways of achieving a similar result that are less cumbersome and awkward. The advantage is that if the public key is leaked it's not a big deal, it can't be used to gain access to the system.