4 ms·
The first difference can be negated by using an unplugged storage device to store the key. The second one is trickier since you need to do processing to prove
by FranchuFranchu 5y ago
The first difference can be negated by using an unplugged storage device to store the key.
The second one is trickier since you need to do processing to prove that you have a private key, so you'd have to send the key to your own computer which breaks the whole point. You could use a separate "key" computer who owns the keys and that computer is the one that proves that it has the private key, but at that point you'd be better off using a normal security key since it's basically the same thing.
- deleted 5y ago[deleted]
- gabeio 5y agoUnless I am missing something, security keys never send the private key anywhere so the computer can not access it. Unlike an unplugged storage device which can be read by malware once plugged in, and need to be read into memory by the computer for use.