My idea for auth with QR codes would work something like:
a) initial setup: user establishes profile with website, including creating a public/private key pair. Public key stays with the service, private key in the user's phone/app.
b) To authenticate, website presents user with QR code containing a token encrypted with user's public key.
c) user scans code with phone/app, decrypts token with private key, signs it, and returns it to service, which verifies token and signature thus authenticating user.
But then all you've done is validated the user on his/her phone... not on the computer displaying the web page with the original QR code. What am I missing?