Maybe Passwords Are the Future
kevincox.ca
kevincox.ca
PAKE supports in the browser would be awesome. Some applications for it:
https://www.researchgate.net/publication/325142389_AuthStore...
(swap the proposed PAKE for OPAQUE)
I don't think for the average user a hardware token is going to become mainstream, nor do I think biometrics is appropriate due to the privacy aspect and spoofing techniques.
I do the same with my PGP key. I keep the "original" key offline and securely stored but I clone the key into my HSMs. That way the devices I use daily and frequently carry around can't be cloned and have strong brute-force protection (although malware could use my key while the device is compromised) and I can still "mint" new hardware devices without updating my PGP key everywhere and worrying about re-encrypting all old data that I still need.
This is definitely less secure than using keys generated on hardware devices but for most of my usecases this tradeoff makes more sense.