All I have to do is trick your folks into testing a ruby / python / perl / bash script for me that will drop a key on your machine, fire up ssh using that key and tunnel back to my host. Now I have full control of your secure (banking, government, eCommerce) environment, completely bypassing 2 factor authentication. Just one link to one of your email distros and up to 10% of your folks will run it.
Combine this with sudo credential caching and now I have root on all of your systems without having to bother finding vulns.
Thx to Prandium for the demo of this simple social engineering exploit.