Right, I don't know how to be precise in simple paragraphs about the ideas here. Basically, though, if you can authenticate from two or more devices (or, in a real sense, even applications on the same device), then whatever compute or secret is doing the authentication has to be copied between them.
A brief dump of my understanding: (Edit to add, I put this dump here largely to see if I actually understand the general landscape. If there are holes/mistakes here, please call them out.)
This was historically done by trusting the user to manage a secret that they attest they will not let anyone else know. In this world, the "compute" was often common knowledge, but hinged on a hard to guess part. This is no different than a credit card, so far. You agree that you will not let unauthorized users have your credit card.
A not surprising hole in this security, was that you had no way of knowing if someone else had your secret. You could do audits, but in general access patterns had to checked by others. (Note, this works better than folks give credit.)
Security keys took the path of making it so that the secret never gets off of the token device. There would be a challenge protocol that you could only succeed if you knew the secret, which was offloaded to the token. If you lost your token, you could not just get a new one. As the secret was flat out gone.
Passkeys are taking a lot of the security lessons learned there, and trying to bring them to the general public. In doing so, though, they are looking to increase user friendliness by letting your secret be managed by their ecosystem. In the case of Apple and Google, they are basically taking the route that, as long as you are sticking to their programs and services, they will replicate a secret for you.
This article is upset that Apple and Google are limiting the replication. Calling it a trap of passkeys. But... what is the alternative that is being pushed?
Note that if the argument is that the increase in security is already enough with existing audits and non verbally communicated passwords, that is probably fine. I got the tone from the article that something sinister was at play from Apple/Google. Sounds like the sinister motivation is more of wanting high security, though?