>But we're implementing the W3C Web Authentication (webauthn) spec and you can already use it in Chrome in place of U2F.
How are users going to differentiate between a webauthn permission request and a webusb permission request? The later can be used for phishing attacks, which appears to defeat the entire purpose of having a U2F key.