For the vast majority of services, dump the passwords requirement then.
Physically stealing a token from me is a much riskier, less scalable attack than slinging hashes from someone's hobby site into GPUs.
Physically stealing a token from me is a much riskier, less scalable attack than slinging hashes from someone's hobby site into GPUs.
Unlike car keys the tokens don't even know what they're for. You can walk around a car park with keys and match the car, these days it'll even remotely blip the lights - but if you have some random guy's Yubico Security Key, you don't even know if he uses Facebook, Google, PyPI, or what, let alone what the account's username/ email might be. Good luck.