If you’re not storing the actual private key in the Secure Enclave but only the “access to it” what’s changed from how Apple’s keychain already manages password syncing to iCloud?
The only benefit (and it’s still a decent one) is that some random website breach can’t disclose your private key.
In the US, only about 34 to 36% of adults use a password manager. Of the ~64% that don't, an alarming 20% reuse the same password across almost every service, and a ton just rely on browser autofill.
If you use a password manager, you are in the minority. Hell, even if you don't use a PW manager and you at least use a different password for different services, you are ahead of most people.
The general population is largely computer illiterate, and have a staggering lack of basic security hygiene.
It moves to the account recovery flows, but that can be much more difficult to phish.
UX usability is far better. With password and 2FA you have at least 2 steps. Here
Open the app: device like phone or laptop just asks your fingerprint or facial and done.
That is a great benefit for average Joe. Some one trying to scam remotely cannot access the account. The 89 year old grandma will say - I just give fingerprint. Done.
Yes, it won't cover all situations. Like if there is sim swap or bank employee does fraud.