The reality is people are not good at creating, managing and using credentials well - and this is an existential risk for most users not realized until it's possibly too late. Any efforts to assist, support and otherwise absolve users of credential responsibility is a net win for infosec (though likely a loss for privacy).
Everybody has a limit. I spent some time in interrogation... once.
They make it hard on you ? - They don't make it easy.
Yeah, it was unpleasant. I held out as long as I could.
All the stuff they tried. You just can't hold out for ever.
How'd they finally get to you?
They gave me a grasshopper. - What's a grasshopper?
That's two part gin, two part brandy, one part crème de menthe...
Please don’t insert commentary when it’s clear you don’t know what you’re talking about
Your comment violates HN guidelines, but as guideline says I assume good faith therefore I have provided details about how you're incorrect on that one.
If one wanted to use biometric data to access a Google Account secured with a passkey, one would:
1. Need to find a device with that passkey on it (or an account like iCloud Keychain or 1Password that contains the synced passkey). Biometric data could be used to unlock the iPhone, in theory. I'm not aware of this being done in practice.
2. Then unlock that passkey. On iOS, biometric data could be used to perform this step, just as accessing the iPhone in step 1.
If you hold the power/volume buttons or do a Find My lock, it disables biometric auth on an iPhone. I assume there are equivalent tools on Android.
So, if I lose my iPhone and someone also scanned my face, they could login to my Google account by generating a face accurate enough to fool Face ID, and only if they did it before I marked the phone as lost.
Titanic has crashed. Microsoft has been hacked. There are no solutions that do not contain bugs. There are no drivers for sensors that cannot be hacked.
Sure hacking a device is difficult, sure. Maybe nearly impossible, but I doubt it. All software has bugs. Some even backdoors. Some data are centralized and kept on big tech cloud storage which is a honey pot for hackers. Once hacker has biometrics data on your phone captured, it could be used. Not only to obtain your passkeys, but outside of your phone.
A simple google search confirms that. There was a biometric data breach. Sure this might not be the best result, but I spend 2 seconds searching for it. Quite generic article, but I think it is sufficient.
https://www.secureworld.io/industry-news/biometric-data-brea...
Quotes
"Facial recognition and fingerprint information cannot be changed. Once they are stolen, it can't be undone."
"Putting all the data found in the leak together, criminals of all kinds could use this information for varied illegal and dangerous activities."
Keychain, iCloud, 1Password... These are just details.
You still need the device/account that the passkey is stored on.