The public comms around this capability has been terrible, at least towards a technical audience. It all focuses on the "key stored on phones with proprietary OS" model, completely hiding how it actually works. I'm sure that's fine for a general audience, but as someone who doesn't trust these big companies with my whole life, it's an extremely repelling message.
Like the very first sentence on the official passkeys website is, "A passkey allows a user to sign in to apps and websites with the same process that they use to unlock their device (biometrics, PIN, or pattern)." I don't use any of those methods to unlock my Linux laptop! What does unlocking my personal device have to do with logging in to websites? Is it reading my /etc/shadow? What's going on here?? Just terrible.
Oh, it's just a keypairing system. Okay. Why don't they just say that?? How you unlock the private keystore is just an implementation detail, not an inherent property of passkeys.
Thanks again for the Bitwarden link, I'm going to play around with it this weekend and see if I can figure out how it actually works without all the offputting, misleading marketing speak.