Comment on Google will now make passkeys the default for personal accounts

a_fancy_kiwi@lemmy.world ⁨8⁩ ⁨months⁩ ago

Someone else correct me if I’m wrong but it works similar to PGP.

Background info:\

Usage:\

  1. You sign up for a service with your email and click submit
  2. In the background, a private key is generated and stored in iCloud Keychain, Google Passwords, or a 3rd party password manager (so all your devices can access it). A public key is also generated and given to the service
  3. Now you try and login. You enter your email and click login
  4. In the background, the server encrypts a challenge, token, or some piece of data and sends it to your device
  5. Your device decrypts that piece of data
  6. At this point, your device either sends the decrypted data back to the server in exchange for an access token or maybe you decrypted the access token (not sure exactly how that will work)
  7. Now you are logged in

source
Sort:hotnewtop