Have you considered that these are different groups of people talking?
I'd like to take responsibility for my part by not reusing passwords, not using weak passwords, not using my passwords on computers that I can't trust (other people's PCs, public computers, etc.), etcetra. There's not a whole lot on my end other than physical security and the possibility of malware (not very likely on my systems which generally rely on a small set of linux & bsd packages from distros' official repos). For critical stuff I do some kind of 2fa or OTP too.
Which is to say, it is almost possible for an attacker to gain my credentials.
Now if you do your part, your company won't leak my password either. You won't allow bots to bruteforce trillions of hashes per second. You don't allow your infra or certificates to be compromised. Don't mail me my password. Don't let some rando in if they call or send an email claiming to be me (unless you're a bank and that someone shows up with a valid government issued id plus passes a basic background check). And so on.
If we each do our part, the system is secure. There is no need for you to block access to my account when valid credentials are presented.
The only time I've had a breach that was on me when I was a kid and ran a fucking runescape autominer. Every other time, it's been on the company; either they get breached, or their "security" fails and blocks me. I don't consider that "too strong" security. I consider that weak security, because the job of security is to ensure secure access, and with no access, security has failed its job. And if you permanently lock someone out, as Google has done many times, it's equivalent to putting the user's data through the shredder. That's incredibly bad security; a complete failure to protect the data.