This seems to me to be a bit of a narrow market. At the upper end of secure machines, USB ports will be physically disabled. And if you're not hyper security conscious, you're not going to bother with a physical key.
So with this, you need to be somewhat paranoid, but not totally paranoid.
> At the upper end of secure machines, USB ports will be physically disabled. And if you're not hyper security conscious, you're not going to bother with a physical key.
The reason that "upper end of secure machines" have disabled USB ports is because they are organization-owned machines that are issued to untrusted employees (often in organizations where all employees are untrusted in the relevant sense). But in the case of first-party machines (e.g., personally owned machines) where the user is similarly security-conscious, that factor doesn't exist. So, really, all you need to be is a security-conscious individual that uses your own computer for things where you have security concerns. (Or, as an organization, be one where the threat profile you concerned about addressing is more external than internal.)
I think I might prefer this to the current mobile authentication. I often find that the times I need to log in to somebody elses computer, is also when I don't have my phone around. A small usb-something which fits in my wallet would be a nice back-up.
Until someone releases a NFC related exploit (shouldn't take long) and then corporate machines have their NFC disabled (open them up and snip the antenna coil with a scissors? Tuned RF field of high enough power to destroy the NFC chip electrically but not damage the rest of the machine? This will be interesting to watch...)
So with this, you need to be somewhat paranoid, but not totally paranoid.