Sort:  

It's already possible to do multisig and one of the keys could be tied to an app or authenticator device. That requires a bunch of design and development which of course doesn't exist. However, in the current structure you can't tie keys to particular operations, so all active key operations would need to be similarly protected, not just power downs (imagine confirming transfers, etc. via your mobile device). This seems mostly fine to me.