The problem of losing physical access to your passkeys is only really a problem if the site chooses to be strict. There can easily be a “Send a magic link” button where you type in your email. It’s the equivalent of “forgot password”. For most systems, it’s already accepted that your security is only as good as your email provider’s is. Passkeys make it straightforward to have an email-less model, but you always could have done the same thing with passwords. No one forced you to implement “forgot password”, it was simply a practical approach that was worth the security tradeoff.
People seem to assume that we should leave that functionality behind in the transition to passkeys but I’m not so sure. It certainly seems more practical than trying to get users to maintain physical backup keys.
The concern about exporting passkeys is valid but you can share via AirDrop. Doesn’t that work on Android now?
Try to give passkeys a chance. I really think the growing pains are worth it.