For all sites whenever you signup for a website a random password is generated. And then when you re-visit the site you use FaceID/TouchID to automatically pre-populate the password. At that point it really isn't a password in the traditional sense.
And for an increasing number of sites it bypasses this step entirely and just lets me use FaceID/TouchID.
> really isn't a password in the traditional sense.
Can it be sniffed out with XSS? Can it be sniffed out over the wire on the university Mitm'd network? Can it be stored on the server in plain text?The user experience might have changed, but many of the security aspects have not.
On top of that, in cases of XSS or a MiTM you've probably already lost and no password alternative will help you.
I wouldn't consider those solutions passwords in the traditional sense.
Or just add an extra email to the account
Adding an extra email account is not always possible. The option is not provided.
For anyone thinking about it: Please don't make it happen.