A slight detour to your original question but I think it is worth repeating that with single sign-on password authentication, your defense chain is as strong as the weakest link: your local PC.
...