Unfortunately OS and Browsers never made the installation of SSL certs user-friendly. Also the requirement for a private key to be accessible by the PC we'd be using doesn't really help, generating OTP/keys on a separate device seems to be the way to go.
There was never any requirement that the private key be accessible from the local computer. Netscape/NSS had pluggable security modules with full support for PKCS#11-style smart cards back in 1998, I believe, so the 20 years ago isn't even overstating things.
There was a real big industry push back then and many expected smartcards to take over, but it fizzled as hardware companies generally doesn't do software well and nobody really wanted the added complexity of extra hardware.
Maybe it will go better now as individual users have a use case, as things like gmail and coinbase supports it, and not just the usual enterprise platforms.