Where is the U2F/FIDO support? The Mac could be using the T2/Secure Enclave to differentiate massively here - same goes for the iPhone and iOS. (The Pixelbook just enabled built in U2F hardware behind a shell flag.)
TOTP is still vulnerable to phishing. Why Apple has been ignoring this when their biometric products are such a great fit for it is a mystery to me.