Which is why a properly working password manager is not a strong defense against phishing.

Correct. The moral of the story is that hardware MFA and/or passkeys are a necessity in today's world. An infinitely complex password and 2FA are no match for attacks that leverage human psychology.

It's a strong defense that this guy decided not to use

User security that doesn’t meet real users where they are is just nerd theatre.

It works for me. I’m unconcerned if it works for anybody else.

It works for lots of people, until it doesn't. You may well fall victim to such a scheme someday.

That’s almost guaranteed now that I made such a confident statement that it works for me.