We had originally planned to go all-in on passkeys for ONCE/Campfire, and we built the early authentication system entirely around that. It was not a simple setup! Handling passkeys properly is surprisingly complicated on the backend, but we got it done. Unfortunately, the user experience kinda sucked, so we ended up ripping it all out...
Question - what do you do when the site is hacked and your biometrics are compromised? Issue new ones?
The password still works.
You don’t have interchangeable fingerprints? Keep up with the times /s