No, you misunderstood me. Passkeys remove the incentive to attack auth infrastructure in the first place, because a database of WebAuthn credentials isn’t useful to criminals compared to a database full of password hashes. This isn’t about the handful of tech-savvy users who know how to protect their privacy anyway, but all the others which constantly reuse their insecure passwords and won’t use password managers.