> so you get to have vital security features like WebAuthn without giving up privacy.
Yes, Chrome phoning home is a concern to me, but a much bigger concern is the lack of mobile extension and adblock support. Defanged Chromium doesn't solve that problem. Even desktop deGoogled Chromium is just an inferior browser when it comes to privacy right now; it has fewer extension APIs than Firefox and it's missing built in Firefox privacy features like containers.
But on mobile, giving up the ability to run extensions entirely? I'm not sure I can substantively argue whether giving up adblocking is a bigger security tradeoff than giving up webauthn. But it's definitely a pretty big privacy tradeoff given the current state of the mobile web.
I don't know, maybe this is a solved problem. I haven't really looked into CalyxOS. Does it patch mobile Chromium to support extensions? Can I trust the devs to do that securely?
----
Edit: so I did look into this, and it looks like MicroG just doesn't support WebAuthn at all: https://github.com/microg/GmsCore/issues/849, https://bugs.chromium.org/p/chromium/issues/detail?id=997538
So if anything, that gives me a lot more confidence to claim that this is not widely supported yet and people shouldn't be calling WebAuthn a universal drop-in replacement for other systems.
Not to say that WebAuthn is bad, I expect these problems will be solved over time and support will widen. I do think WebAuthn is the obviously correct long-term solution. But I think the "virtually all" language used here is not currently accurate. At best I'm seeing some (very small) repos trying to work around the problem, and I'm not convinced it's good security practice to entrust login tokens to under-audited 3rd-party services."