> the problem with hardware tokens is that they 1) Only store a limited number of logins,
1) It's one passkey used over and over, so it only takes 1 slot.
> 2) It is very difficult to keep them in sync- every time you need to add a passkey, you have to get them both out, which makes it difficult to keep one a in a secure safe to keep it safe from damage/loss
2) With SSO used across enterprise exactly like you're talking about, works fine without having to reregister over and over. Been using this and have implemented it myself for years.
3) much cheaper than a phone with a much cheaper recovery path
4) no path is a free lunch, you're always going to be making compromises somewhere, it's the nature of security - it is adversarial
> it's the nature of security - it is adversarial
Yes, this is the issue. People don't like how adversarial security people act, and how they force things onto people. It's fine if a corporation wants to have some internal policy since they're the ones eating the cost if an employee can't work or whatever. Less so if individuals are forced into these wonky setups for no benefit. e.g. now I have to run and maintain and backup a Vaultwarden server just to log into my HSA, which is absurd (I also have to keep an old version of the bitwarden extension around and use that because the latest requires TLS, which is another piece of infrastructure that I don't want). My password manager already generated random site-specific passwords. And for some unknown reason, browsers didn't start with the obvious step of software passkey support in password managers, and then allow hardware keys for the nerds that want that.
Oh, right, because it's actually a lock-in play, and it's designed to be unusable unless you tie your entire life to Google or Apple's cloud platform.