We've recently been discussing a project where one of the concerns was to tighten up on user authentication. The customer raised the concern that by expecting the user to enter just a user name and password that the proposed web application wouldn't be secure enough for the confidential nature of their data, as such an alternative security technique was wanted.