What happens when you upgrade or, God forbid, lose your phone? Do I need to redo everything from scratch like I have to do with my Krypton PGP and SSH keys? That's a no go for me. I'm pretty happy with 1Password already!
I would hope so. Anything less is not secure. (This is one of the basic "problems" with hardware authentication.)
However, the software model allows for pre-arranged cloud sync between multiple devices. Given how Krypton handles PGP/SSH this support isn't there, but there's no technical obstacle.
Plenty of HSMs can export secrets. It's straightforward to have them make a regular export, encrypted such that only the backup HSM can read them.
Edit: You simultaneously made a comment saying almost exactly the same thing, so now I really don't understand why you would say anything less than "redo from scratch" is insecure. Is there an unstated assumption of "if you have no other device"? Because that was not clear at all.
I think you don't get security. When you make something so hard for people to do, they just won't do it. It's like every website having a different password strength policy, people start reusing the same passwords or use 1Password. I upgrade my phone every year. I won't go thru a billion websites on which I enabled 2FA to swap the device. Also, when you upgrade phones at stores, you don't have both devices together for an unlimited time. If you want better security, then 3FA > 2FA, i.e. two things you have, and one thing you know.
I charge $500/hr for security consulting, 1 week minimums, and am fully booked for months out. I have 20 years in security experience. I'd say I "get it".
I specialize in security UX.
Don't mistake my absolute position on what is secure vs what is usable and what will be used. In general I am a critic of U2F.
All the problems you have stated are real, and you are correct, however the way to overcome them is NOT to have the device keep/use the secret "insecurely". Watch Apple's blackhat talk from last year for some insight into the problem and a usability-friendly yet still secure approach.
It's a hard problem, not one that is going to be solved here on HN discussion.
Security is literally spending resources to protect something. Time is a resource. Space in your brain is a resource.
If I want to secure a city, I spend labor and materials to build a wall. If I want to secure my documents, I spend money on a safe. If I want to secure my emails, I spend brain space and time dealing with passwords.
You can argue that the resource <--> security tradeoff is too expensive and that being insecure is a better choice, but just because something is harder doesn't mean it's less secure. People make that choice every day. When someone reuses a password, they are choosing to not use brain space and instead be less secure.
I think you don't get security... along with other things. There are good ways to spend resources and bad ways. And there is a lot more opportunity to waste resources than utilize them efficiently. Krypton is a very bad idea to start with. It's the poor man's YubiKey. My Android has both Krypton and my Google account. My phone has my identity. If I lose my phone, I lose tons more than if I just lose my YubiKey, which nobody will associate with me and give them means to get into my accounts. I cannot even remotely erase Krypton. In general, it is times worse than a YubiKey, but also times less convenient, and practical. Why would anybody use it?
There is. Usability of such a solution would be low.
You just need a device that you tell it some master key, or that can export it for you. eg a true ($$$$$) HSM can do this, exporting keys that can [only] be imported to another device configured for the same security "world".
So, all this fancy security boils down to a notepad again. I am an early adopter of Krypton and I've been sorry so many times that I'm using it for SSH and PGP.