> An NFC-enabled EMV card will happily reveal its entire account number and expiration date over NFC with no authentication whatsoever.
EMV was enabled with the intention of replacing magnetic stripe payments quickly. Together with 3DS on the online payment side, this would have effectively made a card number by itself worthless. Unfortunately this hasn't happend (except for mobile wallets using tokenization like Apple and Google Pay), but given that (at the time entirely reasonable!) assumption, I'd cut the original designers some slack.
Another reason: How would you even implement authentication? There are millions of terminals out there, operated by at least hundreds of different service providers. What key would you use for authentication and how would you hide it in a way that wouldn't eventually be leaked from legitimate terminals?
> issuers accept transactions from EMV (chip)-capable readers that nominally originate from EMV-capable cards without requiring the chip to be
Some issuers do, some don't. That's not the protocol's fault.
> 3. The information leaked in #1 is enough to buy things online (as long as the CVV2 can be found or guessed). Wtf?
At merchants not using 3DS, that is true – but these merchants also bear the full liability for any fraud happening. In the end, it's a prototypical security vs. usability/conversion tradeoff, in the same way that US credit cards don't have PINs, while almost every other market does.