This one seems prone to bias. Out of all the people disagreeing in the comments who actually takes a position against self interest? 1) Security is more your focus than UX, but you agree with the article. 2) UX is more your focus than security, but you disagree with the article.
That said, the arguments in this article makes many dangerous assumptions. Such as assuming that users never use a shared computer (like say the computer in a library), and that you can completely reliably avoid tokens from ever accidentally getting logged.