Can someone explain how does it work behind the scenes?
As I see it, data is stored in a secure enclave separate from the processor and OS. It only provides a match value based on the generated digital private key. So phones will create a separate pair for every site and send the public key with credentials so the server can verify it with the device.
Wouldn't apple have to open source their hardware as well?