Instead of giving them an advice, we who understand how it works should make these things defaults and not let them exposed. What can the users do in a world where banks are asking you to read the CC details loudly in a phone conversation and give them all the details over the phone. Next thing is that there is a fake call from a criminal organization pretending to be the bank. How would a user detect that it is fake? I think security should be about rules and enforced practices rather than advices that they can happily ignore.
> Instead of giving them an advice, we who understand how it works should make these things defaults and not let them exposed.
This is missing the point. The article states the security advice is actively harmful, in that applying it is more costly than the expected returns warrant. Just enforcing those costs on users doesn't help.
Also, even if I did get taken by a criminal organization pretending to be the bank, I'm going to get the money back anyway once I report fraudulent charges. Not much risk on my end…