The fearmongering of losing google account should stop. Yes, some people lose it. There are a larger proportion losing/getting pwned by repeat use. For the majority - just pressing the fingerprint to access an account (like amazon/eBay) via passkey is great.
Fairly technical co-workers - I used to suggest them to buy USB security key few years ago. Now that same fairly technical some how has at least 2 devices with them - so they just skipped the USB security key need - and just use Google (in Android) or iPhone in Apple ecosystem. Everything just works.
Yes, there will be a poor soul that may lost everything with only one device.
It shouldn’t be this way, but it is.
Not everyone has access to server grade hardware.
Until they lose access to that account and then it becomes my problem to solve.
And you need to accept it works for millions.
Yes there are few that used bitwarden and lost everything as their sync using syncthing failed.
I'd love a hardware sold in multi-packs and "born" at the factory with identical internal device key encryption keys (DKEK). I'd love, even more, if a token just allowed you to "commission" new ones w/ a user-specified DKEK on first use.
I'd use one token as a daily driver and store the other(s) in safe location(s), empty of my personal key material. (Or, if I can just commission a new token w/ my DKEK, store a printed copy of my DKEK in a safe location.)
Give the token a mechanism to "type" a backup of its internal state, encrypted with the DKEK, as a USB HID keyboard. That gives me an easy way to backup the token each time I enroll a new website.
If I lose my daily-driver token I just pull a spare from storage, import my last backup, and I'm up and running.
That would kick ass. No "You just need to buy two tokens and enroll them in every website" bullshit.
You would need some out of band way to collect and save your key IDs and publish revocations.
I’m not sure if this would work from a security theoretic perspective, need to think about how the request is signed and transmitted so someone can’t fake a key being “alive” when it’s really “dead”.
I do agree this would be incredibly useful if it can be made to work.
Are there hardware token implementations where mere possession of the token is all that's necessary to use the passkeys stored on it? That's incredibly stupid, and should have been disallowed by the standard, if that's the case.
See my other comment re: the IT industry being fools.
All this hullabaloo taking away user freedom to export keys and backup tokens but physical possession is all that's necessary to use it by default.
We are a ship of fools, the IT industry.