Just spitballing here, but it seems like a good mix of phishing resistance & lockout recovery would be to have passkey-only auth, but with email recovery.
So no password login, but then you can recover your account by adding an additional passkey by receiving an email.
Kind of, but I have some of my most important passwords and account recovery codes duplicated on paper in a secure place. If there was ever a service that only allowed passkey login (do those exist?), you can't print those out.
I wouldn't be okay with that. Say you're setting up a new iPhone with a new iCloud account because you forgot the password to your old one. (Unlikely scenario amongst us nerds, but very very likely outside of our bubble.)
If you want to log into, say, Google, but the passkey flow is the only way in, then you're almost-completely SOL unless you have some way of getting the passkey out of your iCloud keychain and into the keychain of the phone you're setting up.
If you still have your old phone, you can scan the QR code and get in that way. If you don't, then you're completely SOL.
I'd assume open weight models hosted on openrouter aren't being run at a loss. As such, I've been experimenting with them lately and results are pretty promising. Requires slightly more patience and handholding than just cranking Opus 5 in Claude Code, but for the cost saving it's definitely worth it.
But if you make 10 $40m movies and 2 of them make $300m you've spent less for more revenue and a lot more profit, and that's assuming the other 8 make exactly $0
reply