I think think the problem is intrinsic. “Good UX” has to include “easy enrollment” and “some central authority can reset my password” and the failure of either means a user loses
100% of the function of the application.
Look at how end-to-end encryption of email has not caught on although it was possible in the late 1990s, the horror of gpg, or how the NSA gave up on nerfing encryption algorithms because people will always screw up key management. (Che Guevara might have lived to lead another revolution if he hadn’t misused his ‘unbreakable’ one-time pads.)