An interesting article from theserverside.net website.

http://www.theserverside.net/blogs/showblog.tss?id=StopUsingPasswords