> if they didn't validate the damn key type then it would probably just work out of the box
That thought makes it so much for frustrating. ed25519 is the future anyway, it’s hilarious how many cling to RSA (I’ve got nothing against RSA but at some point we’ll have to switch anyway)
as you've described: the U2F functionality is completely useless because if you lose/break your single U2F key then you're completely screwed
and they still have no support for ed25519 keys (which were added to OpenSSH in 2013), unlike every other cloud service
I have to have an RSA key just for AWS (particuraly annoying as I have all my other ssh keys stored in a hardware token)
if they didn't validate the damn key type then it would probably just work out of the box