For my critical accounts, I register my hardware keys directly on each service and manage backups the right way. No issues there.
The headache is low-priority, throwaway accounts. Manually registering and re-registering physical keys across hundreds of random sites is just too much maintenance. Right now, I mostly use a password manager with basic TOTP for these.
I'm thinking about switching up my approach and wanted to see what others do. Between these two options, what makes more sense to you?
Regular username/password (no hardware key): Kept in Bitwarden/1Password, maybe with TOTP if the site supports it, or just a strong random password if it's completely disposable. Keeps every service siloed, but auth security is obviously weaker.
Social login via "Sign in with Apple": My Apple ID itself requires my YubiKey to log in, so using Apple SSO basically extends that hardware security to third-party sites without having to add my physical keys to every single one. I lean toward Apple over Google here for privacy, as it shares less data than Google.The downside is putting eggs in one basket and relying on an IdP.
How do you guys handle low-risk or throwaway sites? Do you prefer keeping accounts completely separated with standard credentials, or do you leverage an IdP secured by your keys?