Quite so. What I didn't bother to expand on, but its clearly the end
game, is once you have a really good password manager then it can
manage other secrets, such as private keys, and since we've cut the
human out of the interaction part of signing in, they will be just as
usable as passwords. But with clearly superior security properties.

I will readily agree that this is why CAs aren't doing research on
client certs, but they're hardly the only actors in this world. My
experience is that client certs do not get focus because they have a
horrible UI, because they shift the user experience from the website
to the browser and because there's no good story for portability (i.e.
moving them between devices). There are also secondary issues, like
privacy concerns.

