I had a small discussion about this idea[1] and I believe that it is worthwhile:
Make private key based authentication useful for logging in to websites. I don't have the chops but introducing private key based auth as an extra can be very worthwhile for some users. So start there and improve the UI until your grandmother can use it.
I believe the biggest hurdle will be private key management. The advantage of using private keys for authenticating with web services that if the keys become unrecoverable the keys can actually changed by the service provider (after sufficient diligence).