This is untrue and if you thought about what you're claiming for a second this should be obvious. The MIT license let's someone do any of the things outlined there subject only to the need to retain the copyright notice and the license itself. I can grab MIT-licensed files and commit them to my repo (e.g., vendoring a dependency). I can also grab the files from an MIT-licensed commit and then the files from the next commit and recreate the history of that repo with myself as the author provided I've met those two conditions. I'm not saying this isn't _scummy_ behavior; it is! But its within the bounds of what the MIT license allows.
Waive. And no, it doesn't but it doesn't require attribution either. So you're falling back on copyright law which is unlikely to protect you here - there's a reason people include licenses, after all.
Nothing in the post you're replying to is about "is 2000 passkeys storable", it's about "if I have 2000 passkeys and I need to move between an Apple device and an Android device, do I need to establish a second set of 2000 passkeys"?
No, the majority will not. If through some miracles, passkeys gain sudden and wide adoption, there will be a day of reckoning come around the next mobile refreshment cycle, maybe earlier.
People break their phones. That is normal experience. Entirely unsupported by passkeys as they are today.
I'm actually surprised we didn't have more pushback for ubiquitous 2FA, as they have similar threat profile - i.e. addressing the tin-foil threats of cybersecurity aficionados, while entirely ignoring the common threats to real people, in particular the one of broken or lost mobile device.
reply