My requirements are:
1. Nothing tied to a specific device, especially one that can be easily lost/stolen/broken like a cell phone or USB drive
2. No biometrics
3. It shouldn't permit anyone, outside the website I'm logging into, to know if, when, and/or how often I log into that site.
I'm pretty sure using passwords with an offline password manager is the only thing that satisfies that, but if someone comes up with something better that meets all my requirements I'd be all for it.
If one is lost you grab a second device.
1. Can't be tied to just one device - Must have backup codes or multiple devices that can act as the same to prevent lockout and aid legitimate recovery.
2. No biometrics - Doesn't survive rubber-hose cryptanalysis. Easily impersonated.
I would add the following:
4. Unable to operate without my interactive, explicit permission.
5. Not a device left online 24/7. Preferably detachable.
6. Not an NFC.
Congratulations, we've just reinvented the emperor's new clothes with very long CSHWRNG-generated passwords or key files, password managers, FIDO2 hardware devices, and backup codes.
Also, biometrics generally can't be revoked. Not nearly enough attention is paid to that, and it's very important, IMO.
In the extreme case, let's say you're using actual DNA. On the surface, that looks impregnable to anyone but maybe your identical twin (barring the "rubber hose" thing, of course).
In practice, anyone who's hacked a genealogy site (as happened quite recently with 23andMe, IIRC), or who's managed to grab your used coffee cup or cigarette butt pwns you forever.
Passkeys should not require MFA either. I see a good enough future for me and it's:
1. Bitwarden with vault password and MFA
2. Everything else within, passkey
I'm completely unconvinced MFA is necessary if the "password manager at top + passkeys for services" mentality is ingrained in everyone. If you offer a service where I sign in with a passkey and also require MFA you better publish an extremely convincing security paper why, or have an infrastructure critical service that burns the world down if someone unauthorized gets in. There is no other justification for that level of security other than to be an asshole.
So yes, they are better but they are still often inconvenient at least when adding a new service.
$ gen-password -len 16 -lower -1upper -1digit -1punct
e$hmvcel9nyghAyw
Another script in the same project generates XKCD-style random passphrases.