Passkeys are a real improvement against phishing and password reuse, but “passwordless” can make the unlocked device the credential. A borrowed laptop with my browser profile, a stolen but unlocked phone, malware on my personal machine, or someone briefly using an already-unlocked browser may not need to phish me at all. They may inherit synced credentials or act through an existing session cookie while it remains valid.
That is a different threat from breaking the passkey, and it is easy to overlook. I’m also uneasy when convenience means syncing identity and browsing-related data by default, especially when the service gives me little visibility into what follows me across devices.
I favor a plain session inventory: service, device, browser, approximate last activity, and token or credential type, with one-click revocation and minimal telemetry—no unnecessary location history. What real-world examples have you seen, and what does your preferred authentication setup actually protect against?