I don’t like how tokens have gradually evolved from a secure 2F device that you carry with you (Yubikey etc) to a single factor “passkey” that’s built in to your computer/phone, or worse, a password manager with export capability.
It should always have remained a second factor device. It’s not impossible to teach people to use these, European banking did it for years. There’s just no will to do it.
If a user doesn’t have a second factor, what should their first and only factor be? The passkey people are trying to posit that a passkey is better than a password as the only factor.
I 100% agree with this.
I have physical passkeys, one attached to my keys and another on my desk at home and I absolutely hate software based passkeys. Every single time I'm asked for a passkey it always ask me if I want to use my Apple Keychain first and I wish I could default to physical.
It’s because we have effective biometrics now, so the need to carry around an inconvenient limiting physical 2nd factor is obsolete (for the vast majority of regular use cases)