upvote
The difference is you can't just copy and paste the private key into a phishing website. The login process validates your private key and logs you in.

Also since the service does not store your private key, it is more resistant to data-breaches as that is one less potential breach source.

reply
They are bigger. Not as easy to guess. More like pretty impossible. It's like not letting the user choose the password. That way they can't have a bad password.
reply
But these same services are the reason why my passwords are as short as they are. They made me use 'short passwords' by putting upper limits on them.
reply
Main difference is that my banking website doesn't make me use SMS 2FA if I use a passkey to log in.
reply