I don't disagree with that, but I am making a different point. Password systems, by their nature, require lots and lots of actions from users: making up passwords, resetting them when expired, making a keyfile and keeping it safe and backed up (if using a password manager), remembering a long and random master password, and the list goes on - e.g. remembering not to reuse passwords or use similar passwords. It's been proven over and over and over and over again that users will not do these things. It's not like password managers are new; they've been around for 15 years, and haven't made a dent. We can keep banging our heads against that wall, or we can give users a solution that doesn't depend on them doing and remembering dozens of technical actions. "This is the key to your bank account. Don't lose it, but if you do, call us." This can work.
And from a technical point of view, all password systems have a weakness of having long-term credentials - a stolen password can be used for months, at any time, until it expires. That part is not fixable.
And from a technical point of view, all password systems have a weakness of having long-term credentials - a stolen password can be used for months, at any time, until it expires. That part is not fixable.