True, but you sacrificed some safety for that. If you're not home, you can only create accounts protected by the keys in your person, and you're one robber (or fall into a pool) away from losing those accounts.
I'd never accept a password manager with such limited sync, and those are usually free. Paying for three hardware keys and still having such limitations is beyond me.
I'm all for hardware keys, and I'd love to use them to replace all my passwords, but I still wouldn't call your setup "adequate" in terms of either cost, friction, or safety.
You can also add the additional keys later. If it's a serious enough account to be protecting with hardware keys, and you only have a couple keys with you, add a note in your password manager to remind you to add your other FIDO keys. You could add that note to the username so you can't login without editing the username and acknowledging it.
It sounds like a non-issue you're turning into a hypothetical concern because... I don't know, you don't like paying a quite modest amount of money for increased security?
Falling into some water won't brick a yubikey anyway.
It’s introducing one more frustrating make-work item for the human. Now I have to remember to enroll all my keys at all the sites I’ve used them for. Totally manual. Totally forgettable.
These keys should act like HSMs and have proper backup and restore. Even if it locked me into a specific key manufacturer (like lost HSM backup/restore functionality does) I’d take that over the idiotic “just have multiple keys and manage keeping them all enrolled manually” story.
Any backup is a copy.
I can initialize a Nitrokey HSM on a disconnected PC with whatever device key encryption key (DKEK) I want (128-bit AES key). I can write that key down and store it in a safe place (broken into chunks, if need be, for my security model). I can backup my keys generated by the Nitrokey to export files that are completely useless w/o my DKEK. I can store those backups wherever I want without any loss of security.
If I lose my Nitrokey device I can buy another, initialize it with the same DKEK, and restore my key backups. (If I really want to I can decrypt my backups using my DKEK.)
If I don’t want to do any of that I can have the Nitrokey generate a random DKEK that is never exposed. Then I lose all my keys permanently when I lose the key. I have the option to choose the model that allows me to backup my keys if I want to.
If the point of the hardware key is to put the owner thru pointless make-work and risk then the hardware key is serving somebody other than the owner.
But they are good for 2FA, which is what I need them for to mitigate the risk of phishing, siphoning credentials from my phone or just stupidity on my part.
A robber would still need the password so I'm safe for my threat model, which doesn't include state actors.
But you are right about one thing: adding those keys to all the important account, and adding a new one when you lose one, is a pain in the butt.
I'm not often creating many accounts away from home, and I'm not often then away from home for long periods of time where this matters. I'm also just not often creating that many accounts.
If I'm out someplace and I need to create an account but don't have all my authenticators, I'll either just go without 2FA for that brief period of time or just go with the authenticators I have with me. Then when I'm home (probably within a few hours) I'll add those extra authenticators.