> the problem with hardware tokens is that they 1) Only store a limited number of logins,
1) It's one passkey used over and over, so it only takes 1 slot.
> 2) It is very difficult to keep them in sync- every time you need to add a passkey, you have to get them both out, which makes it difficult to keep one a in a secure safe to keep it safe from damage/loss
2) With SSO used across enterprise exactly like you're talking about, works fine without having to reregister over and over. Been using this and have implemented it myself for years.
3) much cheaper than a phone with a much cheaper recovery path
4) no path is a free lunch, you're always going to be making compromises somewhere, it's the nature of security - it is adversarial