But why is 2FA superior? I understand that a yubikey seems more secure than the secure enclave of a computer, but that's a very specific factor (yubikey could incidentally be a single factor actually).
Is it just that more is better?
Is it just that more is better?
Traditional server-side 2FA (e.g., "give me a password and a 1-time code") is superfluous in a passkey world, because it's ultimately just a hack to make up for the fact that password-only auth is weak. Key auth is incredibly strong, so a server-side 2FA challenge doesn't buy you much.
Put all of your passkeys in a single repo (as most people will), and you're literally putting all of your eggs in a single basket. Better hope nobody gets ahold of that basket.