| Unpopular opinion: These keys are about selling the idea that physical-based security is somehow magically better. If you have good password hygene (read: a decent password manager) then I'll need to breach your host to obtain it - if you use a security key, I'll have to breach your host and hijack your session which is slightly more convenient but chances are you're royally screwed once you're breached anyway. Sure there's some edge cases where this might work (one-way keyloggers, etc) but these aren't realistic threats for a large majority of people. Somehow a sales team have taken a bullet hole, and attempted to use a square peg to band-aid it. Stop buying stupid products and just use a damn password manager. |
Yes, quite unpopular since keyloggers and clipboard watching malware are probably a threat model to many more people than someone stealing a security key off your keychain.