Does he explain the flaw anywhere?
He says it's "easy to find" but apaprently he can't find it. https://mastodon.laurenweinstein.org/@lauren/111211489395997...
Why is "weak device password" a reason to avoid passkeys, when those users presumably have weak service passwords as well?