A safer login without a password
Passwords are easy to reuse, forget, and type into the wrong website. They can also be exposed in a company data breach. A passkey is designed to remove those weak points.
The website asks your device to prove it holds the right passkey. You approve with your face, fingerprint, or device PIN. Choose “sign in with a passkey”, approve it, and continue — with no password to remember or copy between services.
How a passkey works
When you create a passkey, your device makes a matched pair of cryptographic keys. The private key stays on your device; the website saves the public key.
At sign-in, the website sends a one-time challenge. Your device answers with the private key without sending it away, and the public key verifies the answer. A breached website database therefore does not contain a reusable password.
Why passkeys stop phishing
A phishing site works by looking real enough that you type your password into it. A passkey is tied to the real website address where you created it.
Before signing, your device checks that address. A look-alike site fails the check, so your passkey does not respond. That is a strong reason to choose passkeys whenever a service offers them.
Keep your backup account secure
Apple or Google can sync passkeys, so signing in to the same account on a new device restores them. This is usually the most practical option.
It means your Apple or Google account deserves extra care. Use a strong unique password if it still has one, turn on two-factor authentication, review recovery options, and keep devices locked. Keep a recovery method for important accounts.
The same privacy idea for your files
Passkeys are for online accounts. Sealby has no account or service that you sign in to, so it does not use passkeys directly.
The privacy principle is similar: keep the important secret on your device, not a company server. Sealby applies it to files, encrypting them locally before you share or store them.