Remember Mt.Gox? That's Yubico's most public failure so far :-)
Strong authentication needs to be out-of-band, and support transaction signing, and work everywhere, or there's no point using it. You can't get "out of band" with anything that you "plug in" - that's simply connecting it directly to the same threats.
You also can't get "secure" when less than 100% of users can enjoy it's protection - it only needs to "not work" on one model of iPad, and it opens up the door to support bugs like "I can't log in to XYZ from my iPad 2" - so they need to give customers alternate access methods, like printable codes or recovery/bypass emails etc, at which point the entire protection goes out the window because that's just what the phishing gangs need to bypass it all.
Solving half the problem, even if you paint it blue and write lots of nice publicity about it, does not a secure solution make!