It looks like a good change for the average user, a secret stored on the device is likely a whole lot safer than just having a password. Having it as the only factor seems less secure than password + good extra factor like TOTP on device though. I also wonder how a lost/broken/replaced device is dealth with, especially given Google's less-than-stellar account lockout history. edit : I guess this is still MFA since yo…
Or if you really wanted to, you could flip it. You can allow the Passkey to be the "password" and an actual password the second-factor for the user.