|
|
|
|
|
by aborsy
924 days ago
|
|
I’m not an expert in these protocols, but it’s the public key that is synced. There is no need for the private key leaving the device, in “asymmetric authentication”. Syncing the private key is like “symmetric authentication”, where the hashed password is sent to the website. That’s the old way of authentication. |
|
That being possible means the private key material has to be backed up, as opposed to being permanently locked into an HSM like Yubikey.