But I sincerely hope a requirement for me to use the internet doesn't demand we have a private server instance or a smartphone of any variety (my Nokia candy bar variant serves me just fine).
I can think of many problems we'd need to account for (lack of internet, dead/lost phone, corruption, older folks, etc).
1. Shared secret/Password - He tells me something during registration and then I use that information to verify if he's saying the same thing when he want access the site.
2. PKI - Describes itself.
3. Something he claimed to have during sign-up, so let me check if he has it now.
The problem is, every system is going to have a point of failure/point of absolute control. This is because, you want someone to be able to reset their password/public key/auth token if they forget/misplace/get stolen. Sure, things would be a lot easier if you left the liability on the user, by explicitly stating that if Acts of God (legal term) happen to him, you are not liable. But in this day and age where I see every service tending towards dummifying and hand-holding, I don't see this approach being popular at all.
In the above approach, by pushing all liability onto the user, you tell him that HE and ONLY HE is responsible towards the safe storage of his credential. It's not like in real-life, people can't come up with a gun pointed at you and tell you to give up your auth token, assuming they MitM'ed your password.
My main objection was calling for using a device that is expensive, requires special/additional phone plans, and doesn't _really_ solve the problem (especially for most of the global population). I have a rather diverse set of friends by age, income and technical experience - and smartphones aren't the majority.