Ok, so the big security risk that passkeys are supposedly designed to stop, is actually still there?

If you can still be phished, remind me what the point of any of this was, again?

Ignoring any supposed security benefits, personally I use it because it's much more convenient/ faster than logging in with a password since.

You're still slightly less likely to get phished if you only ever login with passkey and only use the password in case of lost passkey. Of course you could get phished that one time but entering your password once (maybe never) has got to be better than entering it daily.

I don't have any passkey accounts where I didn't start off with a password and after adding a passkey the password login method was always retained. What services are people using where you don't need to set a password?