> Passwords are bearer credentials and as such, they are not a meaningful layer of defense when in the custody of even a modestly competent system administrator.
Again, you are avoiding my argument. Passwords, even pin codes have been a meaningful layer of defense for half a century. You can argue that they are weaker and propose stronger methods such as paddhphrases but you arr arguing against passwords when your real argument is against "what you know" as a factor of authentication.
> As I'd said, you need to look no further than annual threat reports to see that credential theft is the most common avenue of abuse - by a lot.
Are you a middle manager or executive by chance? Because I respond to incidents as a matter of routine and I very much know how much passwords get phished or cracked. You know what solved the problem: adding even the weakest layer of authentication like SMS. Now, there are many better altetnatives for a second factor of auth other than SMS as there are for passwords as what you know being a factor and I am open to that discussion. But what you are saying is you don't get why a weak layer of defense is needed so you want to get rid of it.
> The threat landscape certainly changes but the economics of computer fraud and abuse remains largely the same: attack the most vulnerable link in the chain for maximum profit for the least amount of cost
Again, it's not a chain. Your mindset is a flawed way of thinking carried over from physical security (think "cyber killchain), which is perimeter focused, that's where the chain analogy comes from.
Modern security, having learned from the past few decades is such that you have many layers of chains. The user's knowledge, as weak as it is, is one such layer. Removing it plain and simple is a reduction in your security posture. See, the critical thing you need to get is the relationship between layers od chains as opposed to links in a chain is complementary not symbiotic.
Persistent threat actors will get past any layer of defense. If ransoming your company gets me a few million dollars, as a criminal there is not a whole lot I wouldn't do including physical attacks (there are even untargeted campaigns where threat actors drop or mail USB drives en masse).
> the human and her portable password (and other forms of exportable factors, roughly in order of security: SMS-based, HOTP/TOTP apps, email magic links, Duo-style "confirmations").
Great, guess what that means? They spent all that time and effort to get past a password and now they face a yubikey. The difference in cost to threat actors is at least geometric. They can't just steal a yubikey or compromise your phone, now they also have to steal or guess your password.
By removing user knowledge as a factor, you are making it orders of magnitude cheaper for a threat actor. And you think that is fine because the latest and shiniest methods of authentication, unlike past solutions will never ever be defeated and you will never face insider threats or threat actors willing to spend more to profit off of you.