But those are per site right?
Re hardware and that above is not something for most people:
Yeah I agree. Something like https://uni.horse/notes/solo-key-backups.html, but it shouldn’t be a solution for most people.
But I still think the backup story is flawed, and could be improved to work in a easy and secure way:
Using some easy vendor GUI tool, with a simple clone button:
1: Generate on-hardware webauthn master key on device A. 2: Generate on-hardware key-par on device B 3: Export B’s public key to A 4: Encrypt A’s private key with B’s public key 5: Export encrypted master key to B 6: Decrypt on B
But I guess we ideally would want some standardized protocol for doing this so you can do cross vendor backup.