So take my below answer with a grain of salt...
I'm surprised by all the attempts to replace the password with non-secret keys be they facial recognition (face prints?), fingerprints, or other...
I can login to your facial recognition screen just by holding up your photo. Fingerprints are little more difficult but the technology exists.
But if I am not in possession of your password I'm going to be spending a lifetime cracking it.
Conclusion: Keys are not secrets and can be easily copied. Passwords ARE secrets.
Yes, passwords can be difficult to remember but that's a different problem.
If you want to see secret/password management done right check my website ( http://www.jayfuerstenberg.com )
I agree with your assessment on facial recognition and fingerprints, though the biggest problems with the fingerprint authentication are the lack of ubiquitous sensors and privacy issues.
But password manager software is better than nothing ;)
Is there something that makes a smartcard based USB key work differently when held by a person other than its rightful owner?
My impression of them, perhaps incorrect, is that they are akin to Hanko ( http://en.wikipedia.org/wiki/Hanko_(stamp)#Japanese_usage ). Basically a system of using possession combined with a fairly unique set of data as a means of distinguishing and authenticating its owner. But in practice its far less than perfect.
Nothing is perfect of course. The risk/threat is very similar to someone stealing your phone and has somehow gotten to know your master password to your password management software. However, password management does not really solve neither the usability or the security problems of usernames and passwords ... although a good piece of software can certainly help.
That does reduce the USB key to a single point of failure though. That risk could be mitigated with a proprietary key copier.
A standard way to generate key pairs for authentication would be a lot better though. (Really, there's no reason we couldn't use SSH private keys with some simple client and server plugins.)
There's an implied 'because' between these two sentences, which I think is problematic, since the first sentence does not necessarily follow from the second.
I couldn't care less about the second part, but the first is a great idea. When I visit the website in your profile, though, I don't see any mention of hardware, just software.
Is there more information available somewhere?
The hardware key is in private beta and will be publicly available soon. We have evaluated half a dozen smartcard technology vendors and are partnering with a couple of them, so we can deliver a key with or without FIPS certification depending on your cost consciousness and security requirements. Please e-mail me for additional info.
I'm honestly not trying to spam HN with links to my product but since it's on topic I'll just mention that I developed an iPhone app called KEYBOX ( http://www.jayfuerstenberg.com/keybox/ ). It securely manages passwords and other secrets without dongles or other devices.
USB keys are a good idea from a convenience perspective but what makes it convenient for you makes it equally so for a hacker (the nefarious kind) to break into whatever system you're trying to make secure.