Two factor authentication is a funny thing in 2013. All computer users understand passwords (and the basics of password complexity/secrecy) at this point. That covers the "something you know" factor. Many users conceptually understand a "something you have/are" factor in the form of biometric scans or smartcards. Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting. On t…
His line of work has him dealing with some pretty sensitive material, and a two-factor authentication is required for it... something that, when introduced, was a source for many calls and angry shouting. I could have deferred this to their tech people, but I'd much rather spare them the anguish. ;)
Bottom line: It's getting better, but you are still, unfortunately for us all, way too optimistic.