> If you don't like Google or Apple, use your favorite password manager.
Unless the service you are trying to use requires that you use a particular model of authenticator, which the service provider can enforce via attestation.
> Unless the service you are trying to use requires that you use a particular model of authenticator, which the service provider can enforce via attestation.
Isn't it even worse? Browser vendors don't even offer any way to not use their baked-in authenticator? With WebAuthn they offered at least the options of using a security key via Bluetooth/NFC/Bluetooth as alternatives to the device authenticator. I don't see that option with passkeys.
So, there seems no way to use a password manager with passkeys.
Sure, but passkeys are meant to replace passwords, not SSO (although I won't complain if they do replace SSO).
Most services probably would not restrict you to just one model of authenticator, but it wouldn't surprise me at all to see a service require that the authenticator be backed by a secure element, in which case you could use a security key, a passkey, a TPM, et cetera, but not a password manager. I'd still take that over passwords, but I don't think everyone would.
Unless the service you are trying to use requires that you use a particular model of authenticator, which the service provider can enforce via attestation.