> hence why passkeys were ideally device specific, non-exportable
Not true. The original concept was always for them to be cloud synced.
This has nothing to do with their anti-phishing capabilities. The anti-phishing capabilities come from the fact that the password manager authenticates the application before handing out the passkey. It doesn’t matter if they are synced across devices or not.
You are correct that other login methods might be weaker than passkeys. I’m not sure how that’s related to passkeys though. In real security sensitive applications the recovery process is “go to the bank’s branch and show them your driver’s license”.
> Your master password to your cloud PW manager's vault is also phishable
No, it’s not. You would need to steal my yubikey to get access.
> Not true. The original concept was always for them to be cloud synced.
It was not. The original U2F spec was created before that idea was around and it talked about hardware security keys as means to store the primary key pair.