Earlier quoted context omitted.
It's putting password management into the same basket as the device. Suppose your Apple ID gets compromised. The attacker is a jerk and decides to remote erase your device. Then they use your account for black hat stuff and get it permanently banned, or just erase everything on iCloud too. If the password manager was a different service then you'd still have the password for that service and could get in and recover…
I think you might be making some assumptions about how this stuff works without looking into it. - A lot (most?) people’s Apple Account name is actually their main email address (e.g. Gmail), so they would still control their email address even if their Apple Account was compromised. - You can still recover your Apple Account and iCloud Keychain without any devices (e.g. if phone broke like in your scenario). - Your…
But the login for the Gmail address is a passkey that's on the Apple account...
> - You can still recover your Apple Account and iCloud Keychain without any devices (e.g. if phone broke like in your scenario).
So what's the point of passkeys if you can get access to them without passkeys?
> - Your passkeys stored in iCloud Keychain are still protected even if your Apple Account has been compromised.
How can something be protected when the thing that controls access to it has been compromised?