If it's more convenient to be insecure than secure, users will pick insecure every time. There's a reason there are so many bad password in the top passwords in breach dumps.
I have to tell myself every time I go through some of my login flows that inconvenience to me means more so to an attacker, but most people don't have an adversarial mindset and just want it to work.