>This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security.

I 100% agree - almost everything about them screams "this is The Ideal Corporate Solution".

This isn't a bad thing, it's nice to have a standard for corporate uses. And the attestation-DRM stuff makes perfect sense there, you already have MDM and it fits with that perfectly....... though not all that differently than using MDM to set up client-side certificates. But app/OS support is better, for some reason. Why didn't they just improve that flow?

For personal use though, they seem outright hostile to people living in the real world with common failure modes. It's outrageously clear that normal people were a distant afterthought - just look at how hostile it was to syncing at the beginning, and how long it took to get key exporting (and how directly hostile they were to anyone building a stopgap in the meantime).