No. of Recommendations: 2
Very thoughtful post.
The problem I am seeing with this:
The best way to avoid this is multi factor authentication (or MFA, sometimes two-factor auth, or 2FA). On a phone or dedicated device separate from the computer or other device with login credential
is that 2FA not necessarily requires 2 devices. Most people nowadays are using their phones for everything. So they have their passwords on it, ideally in a safe, and also the bank´s/broker´s 2FA app. If the phone is lost/stolen and the website login + eventually the app´s password (if there is one at all; not so e.g. with Schwab) is found/decrypted all is lost.