corporate employees are typically regular people, and where phishing resistance is most valuable.
if by regular people, you meant "in someone's personal life", i would say phishing resistance is still relevant but agree that loss of access becomes a bigger risk to balance
> if by regular people, you meant "in someone's personal life"
Right, this is what I meant. I used "regular people" as shorthand for that, which I see wasn't a good choice. Next time around I'll be more clear.