> Whereas with passwords, implementers don't have to do any of those choices, the basic implementation already supports all those usage scenarios.
Sure, in that sense the usability is better, but now we are dependent on the website makers to make choices on security (offer good 2fa, don't limit passwords to 8 characters and store it on an ancient mainframe, etc.) and even then the usability can take a hit if the website is ignorant of or actively hostile to password managers (breaking autofill and such). Neither system guarantees a good experience.
With my example I tried to paint what a good passkey system would look like for OP, I am aware that leaving the usability part up to the website will result in such a mix.
Sure, in that sense the usability is better, but now we are dependent on the website makers to make choices on security (offer good 2fa, don't limit passwords to 8 characters and store it on an ancient mainframe, etc.) and even then the usability can take a hit if the website is ignorant of or actively hostile to password managers (breaking autofill and such). Neither system guarantees a good experience.
With my example I tried to paint what a good passkey system would look like for OP, I am aware that leaving the usability part up to the website will result in such a mix.