Re: "Vendor insists passkeys are the future"
"I wish I could say I consistently do all of these; if I'm honest I don't. These problems largely exist because we're trying to graft secure authentication onto non-standardised systems originally created for a thoroughly broken authentication model (manual entry of passwords stored in a person's head into webforms not designed for automation) and it is fragile."
Bingo. Upvote for that. We can't always fully control our risks and despite reservations, we have to accept risk because of requirements to interact with a non-standard system. In the rosy colored world everyone uses the same standards and implements them in a consistent way. However, in the real world that just does not happen.
Its a bit like driving. We have standard signage but the standards can change by geolocation. Furthermore, individual drivers will do what individual drivers will do. I see someone driving unsafe I try to avoid them but sometimes I have to follow their path and add more buffer (distance between cars for example). I have to accept the risk but I still drive defensively within my means.