I heavily support the idea of a better authentication system than username/password. Something more personal would be great.
I'd suggest using something like the thing MyVidoop used to have. https://myvidoop.com/ (I thought it was bancrupt long ago - nice to see it up and running).
Maybe we should make it mouse gesture driven instead of keyboard keys and use pics encouraging them?
Something along the lines of the cicada principle might work better when combined with vidoop-like authentication: http://designfestival.com/the-cicada-principle-and-why-it-matters-to-web-designers/ (just look at the lego army!)
On the technical side it would require us to write a PAM module and a configuration GUI for it + patching OS installer (ubiquity?).