You're joking, right?
That may be too much of a risk for enterprises, but as a personal security key? That seems like a completely reasonable choice to make.
Not all vulnerabilities are equal.
This sounds better than a software password manager, right? Or am I missing something?
> [...] phishing, which is the attack the 99.9% of us have a practical reason to worry about [...]
Both physical and software authenticators protect just fine against that.
Some Mastodon infosec grifter is going to name this "Insider Triple Threat".
While some users may need to buy updated YKs, perhaps having a tier of discounted "vulnerable" new old stock and more expensive patched new stock would make the most economic and utility sense.