This is where password managers are useful because they would refuse to fill in login information since the domain doesn't match
"Dang, this site isn't working right with the password manager's detection. Guess I just gotta paste the password in again..."
Meanwhile U2F/Passkeys can't possibly be abused like this.
I use keepass (FOSS under GPL, fully offline).
It does not detect domains.
"Dang, this site isn't working right with the password manager's detection. Guess I just gotta paste the password in again..."
Meanwhile U2F/Passkeys can't possibly be abused like this.