The user still needs to provide proof that they own the passkey in order to login. It's not like someone could hack the website, steal the "string" and use it to login.