Securing usernames/passwords and handling second factors etc; is already done so well and it's hard to do.
Having a clear 'this is where we can be secure' stances is what makes me want to trust them more.
But what kind of argument is that, if you are a single individual who wants to signup, I am not going to setup my OIDC servers. That is like saying it is a good idea to run a dedicated linux server in a datacenter under your own management, when all you want is a small static website for your mom+pop store. Sure, you can run your own server and it is all open source, but just overkill.
> already done so well and it's hard to do.
So hard that literally all other websites in the world with a login have implemented it. And tailscale is a VPN-like technology company - if they can't manage to implement a login because it is hard, then I would definitely not accept their offerings.