You validate yourself on your device. This can be via biometrics, a PIN, or inserting something like your Yubikey. Once validated, your device generates a unique public/private key associated only with that website. You send the site your public key. The site stores that for later use. Yo...