Earlier quoted context omitted.
That article is about as misleading as it's possible to be while still being technically right. The "attestation" feature of passkeys exists solely to let websites refuse to let you use passkeys tied to hardware you do control, or to software. The way this article only mentions it in passing and tries to downplay it reminds me of the joke of https://what-if.xkcd.com/49/ - a very long article listing a bunch of upside…
I guess we'll have to wait and see whether websites will force people to use specific authenticators. I don't think they will.
You can try this out on webauthn.io and changing the attachment setting.