I replaced the contents of my .htaccess file with the default recommended by WordPress (via FTP): https://codex.www.ads-software.com/htaccess. Then I logged in normally and deactivated “better WP security”.
Honestly, if these steps (taken by “better WP security”) were really required, why would’t WP include them in the default build?
FWIW, previously I could log in using the “log in” link on the site, and it logged me in to https://sitename/wp-admin00000000 (appended with about 8 random numbers). I have no idea how these numbers were being generated, but it was not a “feature” I turned on.