At some point we have to acknowledge that those little RSA random-number one-time-password keyrings are not the answer to our security problems. For one, if every password was backed up with a unique one-time-password token, I would be carrying more of those things than keys on my keyring, and would probably need a big old-style janitor's keyring to keep them all. You know, the kind that's so big you could slide it on your arm all the way up to your shoulder? I'd also have a lot of trouble telling them apart.
Okay, so what do we do instead? Probably the best compromise is SMS as a second factor, since we all have mobile phones. If your objection to that solution is that it's too easy to steal, remember the tokens. They're even easier to lose.
Mokalus of Borg
PS - I'm sure someone could come up with better two-factor authentication.
PPS - As long as it's genuinely two-factor