What I dislike about passkeys far more than any of those qualms is that they can implement remote attestation.

A website should not be able to dictate what application I use for passkeys, what hardware the passkey is stored on, or whether I'm allowed to duplicate my own key.