I've been in tech for 25+ years. I'm very familiar with security, and I have the internal endurance to sit patiently and work through IT-related issues.
However, at this point, there are just too many broken ways and I'm at the point of giving up. I use LastPass and if that somehow gets hacked or phished, I lose absolutely everything. I'm waiting for the next virus or phishing attempt to steal my LastPass password.
I use multi-factor authentication on some accounts, but if they use SMS like many sites do, I can get my phone number stolen from me and then I lose access.
I use Gmail and Google Authenticator, but if I somehow do something to piss off Google, I can lose my gmail account and access to Google Authenticator and then I'm really fucked. I've lost some gmail accounts because they will ask me for security questions when I log in with the correct password, and I don't remember them so my account gets locked, so they're gone forever.
What we need is a single way to do login, MFA and security across every single site. We can't have every company incorporating their own methods. We need standardized customer support, where Tier 1 customer support can't give you access to things like credit card numbers, last 4 digits of SSN, or change passwords. Changing passwords needs to be a higher level, better trained customer support.
There needs to be an ISO standard that is well thought out and implemented by all the vendors, or at least all the big vendors. If there's a standard way of doing security but also a standard way of doing customer support and what data is exposed to various levels of customer support, then social hackers can't take partial info from sites A and B, and use that to social engineer site C.
This has to be simplified because it's absolutely unwieldy even for a veteran like me. There are too many ways I can get hacked and we are all just sitting ducks. The only thing protecting us is that we aren't high-value targets.