MFA could have largely been unnoticed had there been large scale adoption of client side SSL/TLS certificates. This would have required a better UX on the browser side and an account creation process that made creating a CSR locally, transmitting it, receiving the cert and storing it transparent.
Then as long as both the username/password and certificate authentication were required, then password reuse wouldn't matter.