His name was Lawrence David, but I can't quickly find the writeup that illustrates the point I'm making.
I have accounts I haven't logged into for years, but still need access to. Losing access over time is not a good feature. And a 'reset' with antibiotics doesn't make sense for a bunch of reasons.
Also, password diversity is a good thing. I don't want $COMPANY_A's data breach to expose my password to $COMPANY_B
Yes
Example: iPhone (and Andorid) both have "secure enclaves" where cryptographic keys are stored. However when you step into the basic PC/Linux realm the concept of a secure-device for key storage (TPM) is pretty non-existent outside of corporate players. We can do better, without totally going pie in the sky.