Sort:  

Right so why not just use SQRL and get rid of the password for people who don't want to care about passwords anymore?

Access control is by either something they have, or something they know, or something they are, or any combination of that. So you don't really need a password for authentication or access control but you do need their smart phone, or biometric, or something else. If a password must be used then pick a high entropy password. But I think another issue is most people's computers can be compromised so a keylogger would capture them entering in their password anyway.