44 ms·
If you sign up for service X, X will generate a private/public pair for you, give you the private key and keep the public key. Then whenever you want to sign i
by precompute 3y ago
If you sign up for service X, X will generate a private/public pair for you, give you the private key and keep the public key. Then whenever you want to sign in, you need to generate a sequence that can be verified on the other end.
OR it's a seed generator instead of a static password. So you generate a sequence and it's verified on the other end.
IMO it's just a package deal to normalize biometric authentication.
Of course this could be completely wrong.
- AnonC 3y agoThis is entirely wrong. When you sign up any Service X, you generate a key pair and then give the service your public key. Private keys are private, and must be safely in the custody of the user. Public keys are public, and can be given out freely (though it’s advisable to use different key pairs for different services).
- xdennis 3y ago> you generate What do you mean by this? Because if by "you" you mean a closed source program which is automatically updated generates it for you on your device then I think it's more accurate to say "Service X generates it". As an example consider Ethereum. It's supposedly decentralized, but when someone stole a lot of money from the founder's friends, he unilaterally changed the blockchain by pushing a software update to almost everyone. If the keys are created, stored, and controlled by Google on your device, you don't actually own the keys, Google does. You're just renting your phone to Google.