Yet another reason to not enable passkeys anywhere.
https://blog.timcappalli.me/p/passkeys-prf-warning/
TL;DR - If an idiot website uses your passkey to encrypt your data, losing/deleting the passkey will almost certainly mean losing your data.
Of course we should all be backing up our stuff locally instead of trusting cloud services, especially for irreplaceable things like pictures and movies, but lets be real, the average user doesn't.

Please, please, please stop using passkeys for encrypting user data
Passkeys are the future of authentication, but using them for data encryption is a disaster waiting to happen. Overloading these credentials creates a dangerous blast radius that can lead to the irreversible loss of a user's most sacred memories and documents.


Hacker News