2FA? We've heard of it: White hats weirded out by lack of account security in enterprise

"being issued a key fob or something similar, which they have to keep track of, and then read (and key in a code) in potentially low or high light environments."

Yubikey and the like don't have the second objection. Personally I wouldn't allow anyone who can't look after a key access to any sensitive information.

