This article says nothing.
In practice, operationally, none of this is solved. Every website/app/platform handles logins differently. Some are still doing SMS 2FA, some still do passwords, some implemented passkeys in the wrong way, some are doing app based MFA, some are doing magic links, some are doing email codes.
You can't in good faith say this is "solved" when it's just more complicated than ever, and the UX is terrible (passkeys, cough)
Yep, the king is currently SMS, which isn't good.
I like passkeys, but somewhere between websites and browsers, even those aren't used in a consistent way. And idk why there are so many prompts before you're actually logged in with one. The name is also unclear.
TOTP is way worse. It used to be kinda synonymous with Google Authenticator which had insane footguns for losing your codes. Now it's just inconsistent and weird. Like I was trying to set up Github 2FA with 1password, it wanted me to scan a QR code with the browser extension, that wasn't working, so I had to copy some other code instead and paste it into some deep hidden menu of 1password that I needed a tutorial to find. I almost did SMS instead. Most people probably will.
Also don't know why Github requires TOTP or SMS even if you already have a passkey. Probably goes back to passkeys not being mature yet.
The article has quite a bit of "me, me, me, I, I, I" self-promotional content. Which makes sense given it is an advertisement for his book.
I find it jarring to hear that authentication is "largely solved" by passkeys and FIDO, technology that a very very small minority of applications support. Making claims like this combined with the focus on self-promotion is a quick path to being dismissed and ignored.