I'm interested in the "Transition users away from passwords" point that was mentioned but not covered in depth.
Once set up with a passkey, should we be disabling password-based logins for that user? Essentially securing accounts one by one as they move over. (with the long term goal of preventing registration with passwords altogether)
And what does the user flow look like for recovering an account when the private key is lost (stolen device), are we just back to sending an email or SMS with a url to connect a new device (seems like a weak link).
or when the users device is "left at home" (I'm assuming no-device = no luck, a compromise of extra security vs weak passwords you carry around in your head).