The following observation has effective in creating an "Aha!" moment for normies:
"So why are you using a shared secret to verify who you are?"
"I don't! I use a password to login and I don't share it with anyone."
"You don't share it with the site you are logging into?"
"...... Oh."