Hacker News new | ask | show | jobs
by kodt 10 days ago
The difference is you can't just copy and paste the private key into a phishing website. The login process validates your private key and logs you in.

Also since the service does not store your private key, it is more resistant to data-breaches as that is one less potential breach source.

1 comments

But most password programs do this too, if you install the plugin (which you pretty much need if you want those same programs to do the passkey thing, anyways)