Once someone enables a passkey, should a phone number really remain the default escape hatch? It feels like we are adding a stronger front door while leaving a weaker side door open. A SIM swap can move texts to an attacker, numbers can be reassigned, and a family or shared phone can blur who actually receives the code. None of that makes SMS useless, but it makes it a questionable default for recovering a passkey.
I’d have the setup flow offer a second passkey or printed one-time recovery codes first, then let users add SMS if they need the accessibility and familiarity. Recovery shouldn’t quietly rely on something weaker than the credential it is replacing, but making SMS disappear would create avoidable lockouts. Do your own recovery habits justify that convenience trade-off?