I have an encrypted file with website|username|password on my laptop to allow for unique passwords across sites. But it's a pain, and definitely not something everyone will do.
In practice, it would mean replacing most of the world's user-facing computer infrastructure.
The card reader doesn't have to be any more tamper-resistant than the rest of the computer. On a public terminal, it should probably be built like an ATM's card slot (and the rest of the machine should be similarly armored), but on a personal computer it doesn't need to be any more robust than the keyboard a user would otherwise type passwords in with. The card-computer communication is all encrypted anyway, so even if it's built like any old USB peripheral it's still better than typing into a keyboard.
If you have deals with many strangers do you not expect to get your hands dirty in some way?
This was something I changed when I realized that a tax related government agency's machine I was using about 10 years ago man in the middled SSL connections to my online banking. Who knows what was logged and what the retention on that was? I don't have time or the inclination to ensure every relative's / customer's devices are secure, so I use my own or go without.
The first makes your public key useless for security. The second locks you out of everything.
So you've still got to have patterns-of-fraudulent-use detection, and some sort of token-reset mechanism.
Persistent data encryption is another option, but that compounds the key-loss problem in that you cannot access earlier data.
It's shameful that it's so much easier to find tutorials on how to store passwords "securely" (including several tutorials that tell you crazy insecure things, like storing with unsalted commodity hashes) than it is to find tutorials on how to integrate your brand new battling-fairies website game with OAuth for authentication.
I think it's going to have to be legislated:
1. Mandate that all publicly disclosed passwords are collected in a compiled set.
2. Require that any Internet service vendor check against this set on password change revisions, and against different portions of the file, as maintainable, on each authentication.
Known passwords are rejected when set, and mandate changes when detected on login.
Asking a 76 year old mostly-computer-illiterate pereson to come up with a never-been-used-before password simply doesn't work.
This also means mandating password safes on all consumer-grade OSes. Apple already does, Microsoft and Android. For Linux, you might be semi- on your own, though most distros offer several options.
I'd also like to see 2FA via a keyfob generator rather than contact token (e.g., phone, email).