Earlier quoted context omitted.
It's putting password management into the same basket as the device. Suppose your Apple ID gets compromised. The attacker is a jerk and decides to remote erase your device. Then they use your account for black hat stuff and get it permanently banned, or just erase everything on iCloud too. If the password manager was a different service then you'd still have the password for that service and could get in and recover…
I think you might be making some assumptions about how this stuff works without looking into it. - A lot (most?) people’s Apple Account name is actually their main email address (e.g. Gmail), so they would still control their email address even if their Apple Account was compromised. - You can still recover your Apple Account and iCloud Keychain without any devices (e.g. if phone broke like in your scenario). - Your…
But this is an example of not putting all your eggs in one basket. An all-in Apple customer is using Apple as their main email.
> You can still recover your Apple Account and iCloud Keychain without any devices
This assumes that you remember your password, and that the attacker has not changed your password, and that the account has not been permanently disabled for abuse.
> Your passkeys stored in iCloud Keychain are still protected even if your Apple Account has been compromised.
"Protected" means someone needs more than just the iCloud account to get access to them, not that you can re-download them if you lose access to your iCloud account.
It also depends on how your account was compromised. For example, if a thief observes you entering your unlock code and then steals your phone, they have the device they need to access all your passwords too.