From Wikipedia: The FIDO2 Project is a joint effort between the FIDO Alliance and the W3C to create strong authentication for the web.
This is my attempt at a more friendly description of what it is.
What FIDO solves is the problem of (a) phishing and (b) a password being used to prove your identity to a site.
Part (b) is a problem not just because passwords can be used by any attacker who discovers your password, but also because ensuring the server does not know even a hashed form of your password is a worthy goal.
The fix for that is good old public key cryptography – where the website knows only your public key, and you have your private key – and you never share it with anyone. (If you’ve used ssh with keys, it’s the same principle at work there).
So now we want people to log in using this mechanism. (BTW, in principle this is exactly the same as what in the old days used to be called “TLS client authentication”), but this involves several activities that are not easy for a normal user to think about:
generate a private key securely directly on the device that will be used
register the corresponding public key with the website, and connect it with your username
protect the private key on the device so other apps cannot get it
make sure it never leaves the device
unprotect/expose it for the minimal amount of time needed to authenticate the user when he actually tries to login to the site (using a PIN that is local to the device)
So what they do is create an app that sits on your phone and does all this.
Along the way, they engineered the system in such a way that it is impossible to use this private key if the website that the browser is currently pointing to is NOT the same one that was used when registering – this is the phishing protection in action.
Note that unlike a “password”, the PIN mentioned in the last bullet above is never sent on the network in any form, and cannot be intercepted; it is local and never leaves the client machine. Therefore, it does not need to be as complex or as long as a password and does not need to be changed as often.
The PIN is merely acting as a gatekeeper for access to this app (and not your account on the server). Thus it is NOT something that a remote Russian/Chinese hacker can meaningfully use in any way, unlike the traditional password, because it is only useful on your own phone. It merely prevents someone who, say, borrows your phone for a few minutes from being able to use it maliciously.
Basically, the threat model this whole thing addresses is the professional hackers or “state actors” (i.e.,China, Russia, NK, Iran, …) going after thousands of people, not people who are physically near you. As always, if you’re specifically targeted by any government apparatus, they may be able to social engineer you into installing some sort of spyware on your phone, which is a whole another story :)