• MentalEdge@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    edit-2
    9 hours ago

    Doesn’t a normal modern password, hashed, essentielly do the same thing?

    No sane service has your actual password.

    • hperrin@lemmy.ca
      link
      fedilink
      English
      arrow-up
      11
      ·
      edit-2
      7 hours ago

      Yes, kind of. You’re still giving them your password every time you log in. And it’s on them whether they store it hashed or in plain text. With a passkey, you know that even if they’re hacked, they’ll never get your actual private key.

      But, if they’re hacked, your key is probably the least of your concerns.

    • kn33@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      9 hours ago

      There’s a few differences. One is the length. Another is the randomness. The biggest, though, is that in a passkey, the server is verified as well. That means phishing is nearly impossible.