• hperrin@lemmy.ca
    link
    fedilink
    English
    arrow-up
    12
    ·
    3 hours ago

    A passkey is a key pair where you keep the private key and give the public one to the service. Then you can log in by proving you have the private key. Fairly simple in theory. Horribly complex in practice.

    • MentalEdge@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      16 minutes ago

      Doesn’t a normal modern password, hashed, essentielly do the same thing?

      No sane service has your actual password.

      • kn33@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 minutes ago

        There’s a few differences. One is the length. Another is the randomness. The biggest, though, is that in a passkey, the server is verified as well. That means phishing is nearly impossible.