All the complaints made about yubikey and webauthn could be made about 2fa 5-10 years ago. Hardware tokens gated by software (ala yubikey + webauthn) are clearly the next step in auth. It’s an accident of circumstance you even need to buy a yubikey - your iPhone, iPad, laptop, android whatever can do everything a yubikey does. There just needs to be enough demand and time for OS and hardware vendors to come around to…
Yeah. It is mostly about integrating and standards. Private keys in the secure enclave already does everything Yubikey does. All phones already have it. The OSes just need to support FIDO and then we don't need passwords anymore (assuming a passcode lock on device). Essentially everyone would have 3FA (something you know, something you have and something you are)
The best second factors are separate devices with their own screens that indicate what you are authenticating to/for before you provide your authentication.
Of course, nothing ever stops a user from deputizing malware.