logoalt Hacker News

RHSeegeryesterday at 3:28 PM3 repliesview on HN

If you store the key in Bitwarden or Keepass, what makes it different from a password?


Replies

kodtyesterday at 3:36 PM

The difference is you can't just copy and paste the private key into a phishing website. The login process validates your private key and logs you in.

Also since the service does not store your private key, it is more resistant to data-breaches as that is one less potential breach source.

BadBadJellyBeanyesterday at 3:38 PM

They are bigger. Not as easy to guess. More like pretty impossible. It's like not letting the user choose the password. That way they can't have a bad password.

show 1 reply
Marsymarsyesterday at 4:33 PM

Main difference is that my banking website doesn't make me use SMS 2FA if I use a passkey to log in.