> People forgetting passwords isn't a problem that's solved with other schemes.
Sorry, I should have clarified: that was in reference to users being unable to successfully use the parent's hypothetical 'terribly complex 5FA device-based passphrase scheme'. Passwords don't get any blame here.
> Bank account fees, seriously? I can't remember the last time I've paid any.
OK, fractionally lower interest growth then, or less frequent premium bond wins. In any case, the bank is going to find a way of passing the cost of business to you, so you have an indirect incentive for their business to be cheaper to them.
> If our info can be stolen because someone else chose a weak password, the weak password isn't the problem. It's the system that was badly designed in the first place.
That is correct for some kinds of personal information, like how storing documents on a 'cloud' without client-side encryption is a badly designed system for privacy. However, there are genuinely some occasions where a third-party needs to have access to (not just verification of) your information, but also has a responsibility to keep their copy secure. A hospital might need to see your medical records to do its job, for instance.
> The analogy doesn't hold because you have to first show that alternatives to passwords are better for the users, even those in the category you mention.
I completely agree with you. All I'm saying is that a lot of people will try to replace passwords (because we all have an incentive to improve the situation), even if their replacement fails at being better for users!