2-factor auth is great. The suggestion is that if you are only going to implement one factor, it should look more like the "traditional" second factor. Basically we should flip two-factor author on its head. A user-defined password should be the second factor, not the first as is currently assumed.