The difference is you can't just copy and paste the private key into a phishing website. The login process validates your private key and logs you in.
Also since the service does not store your private key, it is more resistant to data-breaches as that is one less potential breach source.