most engineers have trouble implementing simple logins with password. do you really think that having a complex system will be better?
most engineers have trouble implementing simple logins with password. do you really think that having a complex system will be better?
No, this is also incorrect. That's not how public key cryptography works.
>your hardware is useless if key generation is too weak
This is true, which is why you choose an authenticator vendor that's widely trusted to make high quality hardware. If you don't trust Yubico, there are competitors.
>the protocol is so complex that chances are high that even implementations can contain bugs
This is only partly true - most of the complexity is in the browser and authenticator layers, and are implemented by cryptography experts in the browser teams and authenticator manufacturers. Almost all of the server layer complexity can be encapsulated in reusable open source libraries - app developers will only have to implement their business logic on top of it, just like they have to do for password authentication too.
>do you really think that having a complex system will be better?
It will eliminate the problems with phishing and password reuse. That is definitely better in my book.