From what you’ve written you’ve conflated separate things. Passkeys are not related to biometrics. Google wants your biometrics. Full stop. Google is a surveillance mega-corp. Full stop. Why are you still using Google? or Microsoft, which you clearly are uncomfortable with? That’s rhetorical. Don’t answer that. No one’s interested in your pissing and moaning for why you can’t leave this abusive relationship. Passkeys say nothing about biometrics. They’re unrelated.
The surveillance corps implementation of passkeys will always be in their interest. Hardware passkeys are superior to device-locked passkeys that are stored in a TPM. Such schemes are nothing but vendor-lock ins. Oh, I don’t want to buy a new phone; all my logins are stored on this phone. It’s too much hassle. I can’t leave Google’s Android, it contains all my credentials securely. Hardware passkeys have no such friction. I can use them on any hardware.
The surveillance corps software-implementation is dodgy too. They’ve opted not to use some of the spec, which objectively weakens security. They’ll claim it’s for user-ease and whatever else they want to spout. The ease of silently using passkeys to access data they shouldn’t, or to migrate the users passkeys to their new Google android phone–only Google android can migrate you to a new Google android device. You need Google android. Hit me harder daddy.
I mean, really, what are you trying to ask? You clearly don’t trust these surveillance-companies. Passkeys are a good. Just like cryptography is just maths. There’s no issue with the maths or passkeys. The issue lies in these mega-surveillance-corps that parasitically extract value from your computers–whether that’s a desktop, laptop, server, smartphone or some other mobile-computer. You pay for the hardware, electricity, data-connection and you labour on them and these corps take everything from you. That’s why Alphabet, Facebook and whatever other shit software-company has valuations in the billions or trillions.
Security is something they want. They want to be the sole holder of your information. They want a market monopoly. Strong cryptography helps them do that. Much like how a serial rapist and the police both like steel bars: one to keep their victims locked up in, the other to keep their victims locked up in too… huh… point is everyone likes strong cryptography.






I’m also in favor of hardware passkeys & 2FA. They help alleviate vendor-lock in and are more secure.
Usually only YubiKey is mentioned. I do prefer NitroKey’s aims of transparency. If other users know of other vendors please list them.