I like passkeys. I dislike how websites vary the implementation of passkeys.

One thing Ethan misses: you don’t necessarily need one passkey per site. A single passkey protecting Google, Apple, Microsoft, GitHub, etc. can indirectly authenticate you to hundreds of sites via OAuth/OIDC (Sign in with…), while consuming only one resident credential on the hardware key per identity provider.

That makes the “hardware keys can’t store enough passkeys” argument much weaker in practice.

But that's another thing to avoid because now Google can lock you out of 100s of services at once if they ban your account.

We really need Firefox Persona back...