But I'm not sure if I like their 2-of-2 scheme. I would rather have a 2-of-3 one. Maybe I should re-read their paper.
Another thing that bothers me is that it's not very safe by default. The only way to be safe is if you use a (reviewed) plugin and you don't let it update automatically. Because if you use Javascript instead, they can take your key whenever they want. Imagine if the FBI seized their servers and injected Javascript malware like they did with Tormail.