I will defend my engagement bait post: private keys are large random numbers. Authentication tokens are large random numbers. UUIDs are large random numbers. Passwords are large deterministic numbers. Passkeys, 2-factor auth, and similar work off large random numbers. Small random numbers can be guessed quickly. Medium random numbers can be guessed slowly. Large random numbers can be guessed in millennia, which is only considered a long time relative to a human's lifespan. Large "unguessable" numbers is the basis of all computer encryption and authentication. But no number is truly "unguessable". It just takes longer to guess, because it is more obscure. Economics are still in play. "Security" colloquially is relative to human lifespans, but truly no such thing can exist absolutely. Only levels of obscurity exist. Therefore, all security is obscurity. Ya bunch of dumbasses.
View quoted note →