The problem with any key based auth or biometric auth is a user can be compelled by LEO to hand over private keys or open a biometric lock.
Passwords are protected by the 5th amendment.
Passwords are protected by the 5th amendment.
Most people default to what is easiest. Before TouchID, most iPhone users did not lock their phones with a password. Making biometrics readily available and default means more people are walking around with more secure devices than would be if we only encouraged people to use the absolute most secure options available.
https://www.reuters.com/business/legal/us-supreme-court-nixe...
In OpenID, OAuth and OpenID Connect the paradigm is completely different, where your identity is provided by someone else.
OIDC and WebAuthn can work together.