> it's the nature of security - it is adversarial
Yes, this is the issue. People don't like how adversarial security people act, and how they force things onto people. It's fine if a corporation wants to have some internal policy since they're the ones eating the cost if an employee can't work or whatever. Less so if individuals are forced into these wonky setups for no benefit. e.g. now I have to run and maintain and backup a Vaultwarden server just to log into my HSA, which is absurd (I also have to keep an old version of the bitwarden extension around and use that because the latest requires TLS, which is another piece of infrastructure that I don't want). My password manager already generated random site-specific passwords. And for some unknown reason, browsers didn't start with the obvious step of software passkey support in password managers, and then allow hardware keys for the nerds that want that.
Oh, right, because it's actually a lock-in play, and it's designed to be unusable unless you tie your entire life to Google or Apple's cloud platform.