What would be nice is if we could improve the process of generating per device client side certificates that can be associated with a user account. Then we could just use certificate based authentication (and add on password based authentication if we want a second authentication factor).