> But the problem is that you can't really backup passkeys
The individual passkey? Maybe not. But I don't really need to backup the passkey, I can just have backup passkeys or other backup authenticators, including complicated stored one-time passwords.
To answer your earlier hypothetical, I'm out traveling and I'm mugged. Well, hopefully, I'm not mugged in the part of the travels where I'm carrying truly everything at the moment, and I can just go back to the hotel room and re-auth with a device I saved there Problem solved, no big deal. If I lost truly everything while I'm out, I'd do as suggested elsewhere here and call home to get a trusted friend/family member to read me off the one time password saved at home or whatever.
> My issue with passkeys are that they are designed for a reality that don't exist
The reality of passwords being hijacked is absolutely a reality of today and is a constant issue for tons of people.
> I know plenty of people who only have a phone, no other devices.
And I really don't get why we can't also teach these people to also have a little token they use that can also be a part of their online identity. And sure, for certain kinds of accounts have appropriate levels of recoverability, but for the normal authentication workflows its so much better in so many ways.