You're basically describing the status quo; which obviously, does work for the most part. But, there are a couple of elements driving stronger authentication forward; the current lack of a safe and effective cash equivalent for online transactions (anything that is charging a 1-2% transaction fee is not cash equivalent), the desire for executing binding legal documents over the internet (you can in the US have people click [agree] on a web form and be good, but it's hokey and nobody takes it seriously), and the widespread perception that digital crime is endemic.
My guess, based on the nature of the industry is that whatever solution we get will be built on a stack that's already widely deployed (x509 certificates) and that it will be tied to the post office since showing your ID documents to a public official will be part of proving who you are.