It seems passkeys mostly operate in the cloud, like replication across all iCloud connected devices? This seems like a major point of vulnerability for the average user.
Private key infra in crypto/web3 tends to promote best practice as offline, paper wallet, airgapped devices, etc.