

The problems highlighted in the first section are optional however. Forcing a particular authentication / device attestation method isn’t a passkey problem, it’s a provider problem. They are free to do that today with or without passkeys. Equating passkeys = bad because of that feels harsh; it is like any scenario where bad actors behave badly with any given technology.
You might consider something like the friendly elec CM3588 for a DIY option with openmediavault or freenas. I have a big old box currently with spinning metal, but am looking at this as an option now that there are some larger m.2 drives available.