Well written article, good pictures.
"...likelihood of a civil servant leaving my 'strong' password on a USB stick in the back of a taxi or a sacked call-centre underling in Bangalore selling my 'strong' password to the highest bidder."
Passwords don't work like that. The Man does not have your password, so he can't leave it on a USB stick. The System does not store your password, so the underling can't sell it.