> The only way to avoid vendor lock in is to allow passkeys to be persisted unencrypted.
Is this true? Naively I’d expect there to be a two-key solution that would allow Vendor A to transfer passkeys to Vendor B without requiring them to be stored unencrypted. Is the issue just that the two vendors have to trust each other (as opposed to just both being trusted by the user) for that to work?