I don't like passkeys
A security blogger argues passkeys suit enterprises but expose individuals to lockout, ban, and recovery risks that outweigh their phishing protection.
The author contends that passkeys are a strong fit for corporate environments but a poor fit for personal security due to permanent lockout, automated account bans, and device loss risks. Hardware keys cap discoverable credentials at 25-300 accounts, and synced passkey ecosystems tied to Apple or Google accounts remain immature and fragmented. The post recommends password managers with independent TOTP apps for individuals.