One aspect we're not thinking about is the customer service cost to a world without passwords. If you forget your password, they just email you a new one. What happens if you lose your bank's 2FA token and miss a payment deadline? "Too bad so sad," is the HN answer, but customers will move their money elsewhere. So now you need a budget for a call center, replacing hardware tokens with overnight shipping, and the "oops we'll pay the late fee for you", at least in the early days. (Once it's "normal" then those benefits will go away, but who is going to keep their money in a bank where they need to carry around something on their keychain, and if they lose it, they lose all their money? Nobody. You have to really smooth over the jarring transition, and that's expensive.)
Meanwhile "are you sure it's you?" questions are free; pay a software engineer to write them, never touch it again, no matter how many customers you have.
So I guess the question you have to answer, is how can a company make more money off of you by changing how you authenticate? If you show them the $$, they'll show you the WebAuthn.