I’d started thinking of passkeys as the credential an attacker couldn’t sweet-talk out of me. There was nothing memorable to punch into a fake login page, nothing reusable for a phishing kit to scoop up, and the passkey itself didn’t leave a reusable shared secret sitting on some company server waiting for the next breach. The private key was supposed to stay on my side of the login, which made the setup feel pretty airtight.