I'm all in favour of educating users instead of implementing new fangled password authentication schemes. If users don't take security seriously, it doesn't matter how good your authentication system is. They still leave the system vulnerable to exploitation.
