@schizanon
I see that point and that's the reason why I prefer security keys.
The advantage is that if a service (not the passkey-service) is compromised they don't have your paaskey to try with other services and it's more phishing resistant. But you are right: If the passkey-service is compromises ot the user still only clicks without thinking this does not change a lot.