Actually they have been known to profit from community improvements to their old engines as a result of their open sourcing. When they went into the mobile phone games market to create games like Doom RPG, there were already existing doom engine ports to work from, saving them a lot of work. I think that's kinda cool... you never know how these things might benefit you down the road.
I think Carmack talked about it briefly in one of the QuakeCon keynotes. Maybe 2006 or something.
But you still end up paying for the possibility of those disputes in terms of higher prices. If you make a dispute because somebody stole your card and bought stuff, the damage isn't simply undone by a chargeback. The merchant loses out. Chargebacks from identity theft, as you describe, are a massive source of risk to merchants, and they have to factor that into the price of their items. What's more, the credit card companies impose large fees on merchants who get too many disputes against them (even if they aren't engaging in fraud themselves, but instead they are the ones getting defrauded through the process you described).
"... most of the advantages it has over physical / digital cash or credit disappears once you add such things. Once you have a ... physical device governments will get into the game and start regulating"
Not sure what you mean. By 'device' I didn't mean some special hardware developed by some special company, where the government can then regulate that industry. I just meant any computer. I'm saying that signing a transaction can be done offline on devices that are never connected to the Internet, such as an old laptop, or yes even a special device. There's no fundamental requirement to have the keys on your virus-ridden home PC at any time. This doesn't remove any of Bitcoin's advantages from what I can see.
And multi-signature transactions will allow for multi-factor authentication at a protocol level.
That's not really true. You can store Bitcoin keys on paper with QR codes (or even just in your brain), and sign transactions on devices that have never touched the internet and never will. It's just the infrastructure that hasn't been built yet, but there is a lot of development going on to enable the average user to utilize these possibilities. That's not even mentioning multi-signature transaction support.
I think Carmack talked about it briefly in one of the QuakeCon keynotes. Maybe 2006 or something.