Making password entry difficult is like attempting weight loss by eating bland food. It's not the flavour that makes you fat. Nonetheless, there's this perception that something delicious can't be good for a diet. People have this notion that to lose weight, there must be penance . An element of punishing oneself for past transgressions seems essential . Security people have the same mindset. Security must be a hassl…
What you want is that the happy path for security is zero hassle, but the unhappy paths should also drop dead with zero hassle.
This is the UX I really like for WebAuthn / U2F.
All the interactions on the happy path are very smooth. Need a second factor, tap, go. Almost frictionless. On my phone for example you tap the same fingerprint sensor that would ordinarily unlock the phone. Short of not having a second factor at all it couldn't be smoother.
But if this is actually a phishing site or you're a crook who doesn't have the hardware token, it just doesn't work. Still low friction in a sense, but low friction failure. There is no way forward, no override, no "I'm sure", nothing - it just won't work.