Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, hold on. That's not what I implied.

My understanding is that the private key is stored on your own device, unless you decide to use something like iCloud Keychain (which should be encrypted).

The public key, on the other hand, is stored on the service providers' servers. That is used to create a "challenge", which I guess on your phone you will need to "decrypt/sign" with the private key to prove that "it's really you".

That's how I understand it.



Some devices e.g. Apple have a Secure Enclave that is not user accessible, that's what I'm referring to, I'm not suggesting that they are stored on a server.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: