== Standardising support for software authenticators ==
I opened this because of suggestion in https://github.com/w3c/webauthn/issues/1027#issuecomment-470704292.

There should be standardised API for pure-software authenticators. Some of them could be SSL/TLS certificates (if needed they could probably be generated for each RP) and other programs.

This is because currently (and probably also in the future) many people don't have USB 2FA keys and they are not free. Even if software authenticators are less secure than hardware, they are still good and probably better than passwords.

