Earlier quoted context omitted.
> Friends and family can also steal your credit card, but this is not where the majority of credit card theft comes from. This is a false equivalence because knowing someone's credit card data only allows you to do one thing which happens to be pretty detectable: using their credit card for yourself. Knowing someone's password allows you to know one or more of their secrets, including many applications that are virtu…
You're making the false equivalence. There's no reason that using a password/key can't be just as detectable as using a credit card. Also trying to trace logins application side is rather foolish IMHO, this should always be done at the authority that is granting the authorization.
That's not my point. The status quo is that people get alerted if something uses their credit card inadvertently and don't have similar alerts for uses of their password other than in a handful of situations like Gmail logins.
It's definitely not impossible for people to keep tabs on their logins, but this isn't how the Average Joe operates.