elotosh You are right, but not all passwordless solutions are alike.
FIDO and Biometric based solutions dont give of you both -
1. Proof-of-Presence (a user can share his credentials with some other remote person to access a system behalf of him )
2. Proof-of-Interaction (User is consciously choosing to authenticate and is not tricked, forced or accidentally authenticates)
Neither do they provide foolproof phishing protection except for the hardware key based authenticators.
We had considered all these points including lost/stolen device, offline authentication while designing our passwordless solution and the major focus was to remove the passwords from the server and not just from the client side.
I agree Passwordless is not a Panacea (yet), but Paswordless is better & secure in each and every way than passwords.
All the players like Microsoft, FIDO alliance and independent players like us (PureID) are working and committed to make it better.