No, it isn't. A password can be phished, a hardware key can't, among a ton of other benefits. The hardware key is orders of magnitude better than a password.
I don't know, my USB key is on my keychain. Turns out that if you couple your GitHub login to your way of entering your house, you never forget your GitHub login.
Another decent solution is to seed the key, and keep the seed written down or in your password manager. Though I only know of the hacker version of SoloKey that lets you do that. Now you've got the convenience of passwordless login, and the peace of mind that you can always get a new spare.
This is an excellent idea, and I'm still waiting for BitWarden to implement soft-WebAuthn. That way I can just unlock my password manager (or, really, type in a passphrase that will generate the private key) and my browser can take care of all the authentication.
No need to store passwords, you can securely have one password for all sites. You lose the ability of rotating it if it gets stolen, but it's unlikely to get stolen if you never enter it anywhere else.
I would welcome something, but not the so called solutions that go under the buzzword "passwordless".
Shoulder-surfing isn't a problem for me, phishing worked when I was 12 and the internet was new, keyloggers... Yup, possible, although unlikely given the choice of my OS.
But alas, I digress and indeed it became personal, so let's stop it here, as I am not interested in personal discussions on the internet.