I won’t be victim of url jacking since the password manager feels the form. And if it can’t then the domain name is wrong.
And if you steal all the keys/passwords, unlike with pass keys, that’s not enough. I don’t like having all my eggs in one basket no matter how shiny.
Passwords are just a worse, hacky version of passkeys.
*They are private/public keys, so they can’t be MITM.