>passkeys are addressing threats irrelevant to regular people

phishing is very relevant to regular people

Not really that much in comparison to losing access when needed. It's relevant to corporate employees, where phishing is worthwhile to attackers, while losing access means creating a ticket on internal helpdesk and having rest of the day off.

corporate employees are typically regular people, and where phishing resistance is most valuable.

if by regular people, you meant "in someone's personal life", i would say phishing resistance is still relevant but agree that loss of access becomes a bigger risk to balance

> if by regular people, you meant "in someone's personal life"

Right, this is what I meant. I used "regular people" as shorthand for that, which I see wasn't a good choice. Next time around I'll be more clear.

Don’t you remember the giant phishing campaigns like back when lots of celebrities got their nudes in iCloud stolen and published? These things happen all the time, and are incredibly painful. Much, much more so than being unable to share your account with a coworker.

> ...when lots of celebrities got their nudes in iCloud stolen and published?

Right-- high-value victims of targeted attacks. So not regular people.

Regular people get their data stolen all the time, you just don’t hear about it. Just look at the credential dumps and the most common passwords.

I don't get the sense that regular people get data "stolen".

Ransom is the only thing I see happening to end user data.

Credential thefts facilitate theft of money. It might might help the attacker to rifle thru somebody's data to find information that helps answer "secret" questions, to trick friend and family into getting phished, and maybe blackmail, but I don't see a market for end user data that would drive data theft. Nobody is buying end user photos, videos, email, etc. (Anybody who would possibly buy it just tricks/entices users into giving it to them for free to train their AI models anyway.)

LLMs ironically are changing this[0], but at least until now, rifling through random people's data did not scale, so aside for a subset of cases where it was possible to automate access to some services or otherwise leverage them into a scam on the cheap, it wasn't of interest because there was literally nothing useful to do with it.

--

[0] - LLMs, whether multimodal or combined with modern AI-driven STT / TTS pipeline, enable running highly personalized scams cheaply and in an automated fashion, which does scale up and suddenly makes this data important. But that's a very new consideration, one which passkeys were not designed for, because it literally was not possible or conceivable even few years ago.

At the scale you'd expect that to happen, looking at credential dumps, you'd also expect to hear a lot about it.

And yet, you don't. Which leads me to the conclusion that the data dump are overblown.

I think companies around the world come to the same obvious conclusion, which is why these data breaches keep happening, and the companies whose systems were breached are never any worse for the wear.