Edit: got some more details that make this look less bad; see the replies.
I’m not anti-passkey, but I got caught really off guard by a site automatically creating a passkey for me with zero user input. Imagine if I’d logged in on a shared device and now the device owner gets passwordless access to my eBay account!
@misty Yeah, I like the idea of passkeys a *lot*, for specific threat models they're a threat eliminator for entire families of attacks, utterly brilliant.
But their implementation? Hot dogshit, once again by companies trying to trap you into an ecosystem instead of providing something useful.