True. That is a problem. Especially because with Webauthn you can't just enrol a public key. It's one of the reasons I like openpgp for authentication e.g. over SSH. I can just give it a list of public keys to accept without having all those keys actually to hand.