Microsoft could have team up with Logitech like Sony with Erricson, and come up with a standard and put (mildly cheap) finger print reader on each sold keyboard and popularize open source standard for software implementation.
Microsoft could have team up with Logitech like Sony with Erricson, and come up with a standard and put (mildly cheap) finger print reader on each sold keyboard and popularize open source standard for software implementation.
I guess this is slightly easier than typing your email address? But it's not a security feature.
The FIDO/U2F design is a cryptographic key enshrined as a physical key, so rather than "I'm joering2" it says: "I can prove I'm this particular key talking to your site again using mathematics".
Which key? No way to know, but it's the same one as before. Google can't use the credentials it presents to them to get into Facebook and vice versa, the proof from yesterday is worthless today and so on.
Also, you can't revoke fingerprints when they're compromised more than 10 times (20 if you're willing to use your toes too).
Though I'd like to add that FIDO2 does support fingerprints and other biometrics as an additional authentication factor - it all goes under the same abstract "user verification" umbrella as PIN does. The important distinction is that the PIN or fingerprint is never shared with the server - it's only used to unlock the private key - so it's much more difficult to steal.