Some of the common misperceptions I see:
Myth: But what if my cell phone doesn't have SMS/signal?
Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal.
Myth: Okay, but what about if my cell phone runs out of power (added: or my phone is stolen)?
Reality: You can print out a small piece of paper with 10 one-time rescue codes and put that in your wallet.
Myth: Don't I have to fiddle with an extra PIN every time I log in?
Reality: You can tell Google to trust your computer for 30 days and maybe even longer.
Myth: I heard two-factor authentication doesn't work with POP and IMAP?
Reality: You can still use two-factor authentication even with POP and IMAP. You create a special "application-specific password" that your mail client can use instead of your regular password. You can revoke application-specific passwords at any time.
Myth: Okay, but what if I want to verify how secure Google Authenticator is?
Reality: Google Authenticator is open-source: http://code.google.com/p/google-authenticator/
Hmm. Maybe I should throw this up on my blog too.