Correct me if I'm wrong, but won't WebAuthn with hardware tokens still be vulnerable to MITM phishing attacks? Ones where the attacker sets up a convincingly fake website and forwards the signature to the actual server?
I think that's mostly right anyways. There's a very helpful explanation somewhere upthread and that's what I understood from it.