Also, you wouldn't be able to log into a public terminal.
Also, you wouldn't be able to log into a public terminal.
"Also, you wouldn't be able to log into a public terminal."
Actually depending on capability (no pun intended) I could easily see 'read' access being usable without the key but recognize the issue there. The real 'issue' if you will is universal appeal/buy-in which is to say if anyone can use it then you will get some early adopters who will provide support as a differentiating factor and that can drive adoption into more slowly changing markets. Because it has to be everywhere to be effective it won't be a big money maker (this is where a lot of VCs stop listening :-) basically the barrier to implementing it has to be 0 and the value to the implementor has to be non-zero. Given how thinly marginallize 'security' fixes are, this margin won't leave anything for the manufacturer in terms of on going revenue so the key itself has to define the value for the company. (I've actually thought a lot about this :-)
So to your point, for early adopters the experience would be to get a 'key' and to install a plug-in and then enabled sites and services would be secured. Pretty easy sell to an enterprise if their only cost is the 'fob cost' and there isn't some giant consulting revenue stream attached to it. For big companies it has to be completely implementable (once the key infrastructure is set up) in a way that is custom (and probably private) that enterprise. That gives their IT folks confidence and it makes the risk low.
For more general engagements like PayPal or Facebook its a bit different. On things that are appifyable (if that makes sense) there is a potential for differentiation (look at how the World of Warcraft Authenticator stuff was worth it for them to implement).
The key for me is that the existing way of doing things is under attack and it will eventually succumb, when it does there is a tremendous opportunity there.