Your master password to your cloud PW manager's vault is also phishable (hence why passkeys were ideally device specific, non-exportable).
Its phishing resistant not phishing proof
Not true. The original concept was always for them to be cloud synced.
This has nothing to do with their anti-phishing capabilities. The anti-phishing capabilities come from the fact that the password manager authenticates the application before handing out the passkey. It doesn’t matter if they are synced across devices or not.
You are correct that other login methods might be weaker than passkeys. I’m not sure how that’s related to passkeys though. In real security sensitive applications the recovery process is “go to the bank’s branch and show them your driver’s license”.
> Your master password to your cloud PW manager's vault is also phishable
No, it’s not. You would need to steal my yubikey to get access.
> Your master password to your cloud PW manager's vault is also phishable
... which is why all sensible cloud vaults have a separate enrollment key, requiring an explicit action to grant a new device access.