Passwords with 2FA are simply better and more freedom friendly.
Passwords with 2FA are simply better and more freedom friendly.
UPD: oh, heck, attested passkeys are actually already in the protocol. Why can't we just have nice things?
I believe that by allowing password managers to store passkeys, the whole purpose of "device based security" got lost..
And yes, I know the happy path of password managers uses host-based autofill which does add some friction to phishing attempts, but given the prevalence of unexpected but legitimate urls with weird alternate subdomains/SSO/redirects in modern login flows, you have to manually autofill/add an exception often enough that it's possible to let your guard down once at the wrong time.
Though realistically I use a passkey for services I care about and a password manager for the rest.
How often do people lock themselves out of their own house? Don't you know anyone with ADHD? Imagine any time that happens it is mathematically verifiably permanent as a fact of reality itself. It doesn't matter that the state still views you as the legal owner, you are never allowed in ever again.
But if true, that means that Google can choose to not provide you a recovery service, which is functionally the same as them not having it.
If Google does want you to be able to log in then they will work with you to make that happen, whether you forgot your password, lost your passkey, or your carrier pidgeon died.
Passkeys are not special in this regard at all. What does make them special is that nobody can use a phishing attack to steal your passkey and log in to your account. Nobody can guess your passkey and log into your account. Nobody can intercept your passkey in flight and log in as you. That's the important distinction.
Even if you throw your phone into a volcano and buy a new one, you can still receive SMS verification.
Passkeys only very recently got relatively broad support for migrating data (after years of promise and no support at all), and they report (optionally with hardware attestation) what password manager you're using so sites can force specific ones.