How well does password recovery work in those scenarios?
How well does password recovery work in those scenarios?
You might argue "but if they still have the recovery methods isn't my account only as secure as those" and to that i'd point out that you're still way ahead with passkeys simply by not entering passwords on a routine basis. The recovery methods tend to be two factor as well, just without passkeys as one of the two factors (hence email+password) so still a win over password alone in any case.
Passkeys should be thought of as no different to the old two factor authenticators. I mean that's literally what they are, essentially the latest fido standard that allows devices such as your phone to be a hardware security key in its own right. These always had ways to do account recovery with all the providers.
Basically, when the system prompts to pick a key, click the "log in with phone" button, unlock your phone, and select the account/click "OK" to authenticate. The first time you do this, you need to scan a QR code to pair the phone to your computer, but after that you can use your phone whenever you need it.
Passkeys on Linux (and probably even more so on the more niche systems like the *BSDs) can use some love, especially when it comes to CTAP2. Chromebooks are probably the only Linux devices with native support for that.
If you want to safeguard against a fire, use a passkey provider that does exports (i.e. Bitwarden, KeepassXC) and then treat those exports the same as your password database file.
It's also not a good idea to store the backup at home – house fires are unfortunately a thing, and chances are you might not have time to grab either your main or your backup key.