Yes, thank you. Maybe I am getting old but password+yubikey/webauthn was really top UX.

> Maybe I am getting old but password+yubikey/webauthn was really top UX.

It most definitely isn't. Any 2nd factor that is not the device I am currently using (either a yubikey or my phone) has a non-zero chance of not being near me when I need it, leading to the constant question of "where the fuck did I put that darn thing", only to find out that the cat has decided to believe the yubikey is a mouse and tried to devour it, the phone's battery went dead...

What prevents passkey being used alongside password (+ email 2fa)?

Email 2fa otoh is the worst UX I have experienced. I curse every time Claude sends me a magic link. Absolutely hate them.

You don't like not having to worry that they don't store your creds so they can't lose it?

The creds they store hold no value. These creds only give access to their system anyway. They store the email address either way so the situation is no better but less convenient.

They hold no value precisely because they don't store them and send you a magic link! If they stored a recycled password or its hash, then it would be valuable.

Yes but I use separate passwords and webauthn is per domain as well.