I like passkeys.
I dislike how websites vary the implementation of passkeys.
One thing Ethan misses: you don’t necessarily need one passkey per site. A single passkey protecting Google, Apple, Microsoft, GitHub, etc. can indirectly authenticate you to hundreds of sites via OAuth/OIDC (Sign in with…), while consuming only one resident credential on the hardware key per identity provider.
That makes the “hardware keys can’t store enough passkeys” argument much weaker in practice.