Long strings in password managers was a shim until Passkeys got here, because passwords suck. This is a well worn path in enterprise with PKI. Passkeys are PKI for the Average Joe. Folks here will always have esoteric auth use cases, but you design for the average on this topic (consumer auth).
https://passkeys.2fa.directory/us/
https://bitwarden.com/blog/a-closer-look-at-password-statist...
> 19% of respondents said they used “password” as their password (!!!)
> 52% use easily identifiable information in their passwords, such as company/brand names, well-known song lyrics, pet names, and names of loved ones
> Best practices are still diluted by bad habits, with 85% reusing passwords across multiple sites and 58% relying on memory for their passwords
> A majority (68%) of respondents manage passwords for 10+ sites or apps and yet 84% of respondents reuse passwords
> More than half of respondents forget and reset their passwords on a regular basis
> Around a quarter (20%) were affected by breaches and a majority (80%) were prompted to reset their passwords
> Over half (56%) are excited about passwordless options, and 50% are using or would use ‘something you are’ forms of passwordless authentication