1. Shared secret/Password - He tells me something during registration and then I use that information to verify if he's saying the same thing when he want access the site.
2. PKI - Describes itself.
3. Something he claimed to have during sign-up, so let me check if he has it now.
The problem is, every system is going to have a point of failure/point of absolute control. This is because, you want someone to be able to reset their password/public key/auth token if they forget/misplace/get stolen. Sure, things would be a lot easier if you left the liability on the user, by explicitly stating that if Acts of God (legal term) happen to him, you are not liable. But in this day and age where I see every service tending towards dummifying and hand-holding, I don't see this approach being popular at all.
In the above approach, by pushing all liability onto the user, you tell him that HE and ONLY HE is responsible towards the safe storage of his credential. It's not like in real-life, people can't come up with a gun pointed at you and tell you to give up your auth token, assuming they MitM'ed your password.