Isn’t this a classic example of the fragility of biometrics? If I move to a new device, iOS should be required to give up whatever secret key my face translates to, so I can log into websites. Simplistically, if iOS silently turned my face into the web password “g0rG0il3r”, when I eventually migrate from iOS to something new, I’ll have to be able take my face password with me, thus exposing that my face was only ever…
WebAuthN is not supposed to be the only way you log into a service. The credentials are permanently tied to your Authenticator of choice, which can be lost or stolen at any time. If you change devices you just provision the new one for your account after signing in with a traditional username/password(/2nd-factor).
Though, I agree lost and stolen devices are a problem whose solution space needs more exploring than simply multiple auth devices.