Tie everything to apple/whoever is pretty darn dystopian. And the "second factor" as described in this article doesn't exactly sound enticing.
Tie everything to apple/whoever is pretty darn dystopian. And the "second factor" as described in this article doesn't exactly sound enticing.
https://www.w3.org/TR/webauthn-2/#sctn-privacy-consideration...
However Passkeys puts apple in a position of the Authenticator which is the riskiest part in terms of privacy.
A different authenticator is paramount but the question is how secure and private a self-hosted solution can be, with reasonable effort.
If you're more interested in WebAuthn privacy more generally, there's quite a bit of it in the WebAuthn specification itself, since it was an important goal of the design.
No, you can not. Because they are completely broken for a lot of use-cases, especially when you can only add one or two of them makes them worse than even passwords in many situations.