> Account recovery works the same with passkeys as with passwords … get a link sent you via email

Making the email account, an often attacked resource that is always online, a single point of failure. I don't mind relatively unimportant accounts being that weak, for instance where the only reason to have an account at all is to separate your preferences from someone else's, and you don't actually care about security, but for accounts where there is significant PII or payment details or other sensitive information it is a terrible idea.

A second problem with this is that for many their email account is the same as their account where their passkeys are backed up. What if you have lost your passkey due to Google locking you out for no readily apparent reason and you don't have the online influence needed to get them to take you seriously (instead being trapped in the support bot loop)?

I still run my own mail server, and if I didn't my important mail accounts wouldn't be with someone like Google (I do have a gmail address, but that account is only really used for testing other accounts when needed), so that isn't a problem for me, but most people can't be bothered with that faf¹ so usually end up with one of the big providers.

--------

[1] It isn't actually that much faf², until those occasions when it is³, but more faf than most people care for, especially those that don't enjoy tinkering with technical matters.

[2] Just quietly ticking over as long as I remember to regularly verify it is patched up-to-date, and keep an eye out for zero-day issues concerning the parts involved

[3] When there is a deliverability problem, where I host it has problems so I need to make sure the backup is synced and then switch over to it, when there is a relevant zero-day and I have to rush a patch in (or take other remedial action until a fix is available) then investigate to make sure I wasn't quietly affected, etc.