You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)

Unless of course, you need to unlock your password manager, which is not integrated with your browser, because corporate IT doesn't allow browser extensions or desktop apps so you're bound to a web app ...

Ha, I don't need to type 123456, it's stored in my navigator's password manager for convenience. Checkmate.

I don't type 123456 either. I stop at 5.

Next step in typical security team fashion: Prevent password managers from working, by obscuring the password field, using click-to-type passwords or similar shenanigans, because fuck you, that's why...

You need a better team

We can't have nice things.

Until security forces the password manager session to expire after 1 hour, and forces the master password to be 16 char long with a combination of lower, upper, digit, punctuation, moon phase, astrological sign. And then they force you to change it every 2 months, and you can't reuse it until the next time Halley's comet is in the solar system.

You're missing the systemic problem the parent is talking about.

None of those hypotheticals apply in a company where "123456" was allowed as a password to begin with.

And if even if they did, which of these two is easier?

1. Typing your 16 char password with the current moon phase once an hour, and remembering the new one every time a comet passes

2. Pressing your password manager keyboard shortcut (or tapping your yubikey) once an hour, the exact same action that never changes for the rest of your life

> None of those hypotheticals apply in a company where "123456" was allowed as a password to begin with.

True.

> And if even if they did, which of these two is easier?

You didn't understand their point. The password manager itself locks and tapping doesn't work until you put in the master password again.

The fact that password managers can be implemented badly, doesn't mean we shouldn't implement them well.

Yes, but at the same time we need to remember that "password manager" can only do so much if reducing friction isn't a priority.