Earlier quoted context omitted.
I thought "Two-Factor Authentication" referred to an RSA SecurID or something similar. Am I wrong? Why do you say "it's usually misused"?
A SecurID would work. ("Something you know, plus something you have or something you are.") The majority of the cases where I've seen it used so far are in websites or other services that are just asking you for a second piece of information you know -- like a challenge question, passphrase, or the like. ...it looks like Firehost is using Phone Factor ( http://www.phonefactor.com/ ) for their second factor authentica…
We had looked at iPhones for CC processing over cellular networks, but the lack of a consistent signal killed that. Which sucks because that would have been much easier and cheaper as a temporary solution than what we are doing now.