OpenIDConnect is integrated across several platforms, and allows for us to centralize authN and authZ behind a single secure trusted Identity Provider, such as google auth, facebook auth, github auth - whatever make the most sense for your audience. It's the same idea as password-manager, a single trusted login, but better, because there's no password-management nonsense.
I'd argue is not the failure of user, but, the failure of the tech community.
So what I am hearing from you is "user authentication" is your greatest security challenge?