@whitequark @glyph @mcc How does this workflow work with passkeys where the domain won't match? I would assume some kind of redirect to SSO-like thing on the canonical domain, which is how it should be done with plain passwords too (rather than training users to get phished, as you noted they're doing).