Is probably the best explanation I could find.
But also a random company decides, in a closed source way, what your secret is, and you trust them. So key derivation, signing, and that stuff depends on this detail that the random company decided for you (though some closed-hardware devices allow you to generate them on the closed-hardware devices themselves).
If I am wrong, I would love to be corrected.
Most of the basics are the same: pick a password (passkey) manager you are comfortable with. Most people will pick the one built-in to their most personal computer's OS (their phone's OS) and/or their favorite web browsers. The "passkey manager" you choose becomes in charge of generating the thousands (or more) keys you need for all the websites you might use. The "passkey manager" you choose becomes in charge of synchronizing them between devices, helping recover them when you lose access to a device, making them temporarily available to devices that you don't want to synchronize everything to. (Other than that last one and its new QR code workflow, these "passkey managers" are doing it all almost the same way as "password managers" always have. For instance, Apple's iCloud Keychain is largely the same technically whether it is managing/syncing passwords or passkeys.)
There are passkey managers that aren't from the major OS vendors to try (1Password is a major vendor here, of course; other existing password managers are working on it, too) and open source ones to try to learn. It's all based on open standards and most of the password managers in the world can "upgrade" to be passkey managers if they wish to.
A related point I missed, too: given the assumption that everyone who is secure is using a password manager 100% of the time, the best way to encourage everyone to be secure, including average users, becomes "make it easier for, if not force, more average users to enroll in password managers". For better and worse, despite "no human on the planet can remember enough passwords to be secure" there's still a lot of human over-confidence that "we can do it", so making the case for password managers has been an uphill battle in some cases among average users. Passkeys present the opportunity "fix that bug" in password manager roll out. I know very few people with delusions that they can do elliptic curve calculations and/or remember large primes and can do large prime multiplication in their head enough to do private key math the same way that people think that they can remember passwords.
The password manager stays the same recommended toolkit, but with passkeys there opens the opportunity to get the UX right and get even the most password manager skeptical enrolled into a password manager. Whether or not we succeed or squander this opportunity is still an open question, but that's some of the HN excitement about passkeys is that this is an opportunity to make the average user more secure for the good of all users. (A rising tide lifts all boats, as the saying goes.)
Imagine you and your friends have a special clubhouse. You wouldn’t want anyone else to come in, right?
At first you all decide on a secret word to use that you can whisper through the closed door. This way the friends that are already in the club house know that the one standing in front of the door belongs to the group and lets them in.
One day that secret word gets out and kids who shouldn’t be are in your clubhouse. After throwing out the baddies, you come up with a new secret word and make sure to tell it only to the right kids.
Some time later you find more cool kids to join your clubhouse and maybe there are kids that you no longer want to be friends with. It gets hard to constantly come up with new secret words and share it with only the kids you want in your clubhouse.
So you have the idea to give everyone their own secret word. This way, if one of those secret words gets out, you don’t have to make a new secret word for all your friends.
Soon nobody can remember which secret word belongs to which friend. So you need to collect photos of your friends and make drawings of their secret word on the back of their pictures so everybody in the clubhouse can make sure that the right friend is using the right secret word.
Everything is good for a while and then somebody breaks into the clubhouse and discovers all the secret words and how your friends look like that these words belong to.
To not have your secret words revealed in such a way ever again, you come up with a clever way to hide the secret words in a drawing of something else. So for example one of the secret words is „water“ and you draw a fish. A fish lives in the water so you know that the secret word is correct.
But the secret clubhouse is not very secret if anybody, who can break into it, can find out who belongs to the clubhouse by looking at all the photos. The way you solve it, is to remove all the photos and keep just the drawings making sure that each friend’s drawing shows things coming from a unique secret word.
To make it really safe you decide to never have anyone say their secret word out loud. The way you do this is to always use a thing that comes from the secret word. So when their secret word is “water” you let that friend say “dolphin” or “octopus”. One of the drawings you have in the clubhouse still shows a fish that also lives in the water. This way you know you can let them in.
Like SSH keys there is a public and private key pair, and you never actually send your private key to the website, rather it is confirmed in a challenge/response pattern that proves you have the matching key.
This means you can’t accidentally give your passkey to a phishing website or lose it in a data breach (of the website you are logging into) because it never gets sent to a website in the first place.
You can register multiple passkeys for a given website/account.
You can sync and share passkeys via password managers like 1Password, iCloud Keychain, KeepassXC, etc.
OR it's a seed generator instead of a static password. So you generate a sequence and it's verified on the other end.
IMO it's just a package deal to normalize biometric authentication.
Of course this could be completely wrong.
What do you mean by this? Because if by "you" you mean a closed source program which is automatically updated generates it for you on your device then I think it's more accurate to say "Service X generates it".
As an example consider Ethereum. It's supposedly decentralized, but when someone stole a lot of money from the founder's friends, he unilaterally changed the blockchain by pushing a software update to almost everyone.
If the keys are created, stored, and controlled by Google on your device, you don't actually own the keys, Google does. You're just renting your phone to Google.