I love Lemmy and Voyager and the Fediverse. That said, if it were to become mainstream I forsee some problems. The fact that the login relies on only passwords is pretty terrible. Also, this makes the service vulnerable to bots, sock puppet accounts, brigading, etc.
What would you propose replace passwords to not be susceptible to those things?
I personally like how secure and non intrusive passwords are, especially when using a self hosted password manager synced with git.
Passkeys are much better. Unlike what FAANG companies want you to believe, they do not have to be tied to a device. Use a password manager that supports them (BitWarden) and pretty much never get hacked again because of a password. Website doesn’t need to store anything that an attacker can use. No downside.
I’d much rather use a password and a two-factor auth via TOTP code. It’s fast, portable, I can store them on a variety of open source apps, and it’s very hard to hack. I don’t need to use a specific provider, or browser. Flexible and free.
Passkeys in their current implementation are comparatively a mess. Here’s an article that runs through many reasons why: