I attach my suggestion for in-browser secure 2-way authentication that is resistent to online and offline attacks. Please also see my collection of threats that all authentication technologies need to consider in order to be secure, which is published here: