I dislike passkeys because they support remote attestation. It's my key -- why does the website care what app I'm using to host it or if I'm allowed to copy it? Or what operating system I'm using, for that matter.
Because of this, I will not use passkeys. It's a slippery slope. Once we're all on passkeys, website devs won't resist enabling the remote attestation bit, locking out linux users.
Here's the trick when driving on highways to clear up traffic jams: try to move at a flat, constant speed, such that by the time you would reach the stopped car in front of you it has already started moving again.
To the people behind you, traffic appears to be moving at a constant speed. The wave stops propagating backward and the jam clears up.
This is going to wind up with remote attestation being implemented into web browsers to prevent this exact thing (and conveniently for google, this will finally end adblock)
No, nobody can be held liable for the extinction of humanity, for there is nobody left to pay up. If your objection is that you think AIs won't cause human extinction, you should say that instead, as that would be where you disagree with the authors.
be that as it may, when e.g. TicketMaster asks me if I want to "use a passkey," they are potentially referring to something with remote attestation capabilities.
Okay let me withdraw slightly. What I mean is: if I choose of my own free will to not be able to access the bits (e.g. via a cryptoprocessor) then sure, I can still "own" it. And that's the case for certificate authorities. But when vendors force me (with remote attestation) to not be able to access the bits, then I see that as me not having control => me not owning the key.
There are also non-transferrable passkeys which can't be copied between two secure devices, so it'd be hard to get some passkeys onto your yubikey in the first place.
Furthermore, I personally feel that if you can't actually access the bits, you don't truly "own" it.
that's not true. Passkeys have an optional remote attestation capability, which second parties can use to completely enforce aspects of your keys, such as them being non-transferrable or not usable without a screen touch etc.