Earlier quoted context omitted.
> That’s part of the design though. That’s what completely eliminates the ability to do phishing-attacks. If the actual domain name is used to generate the key that would also completely eliminates the ability to do phishing-attacks. Paypal.com and PaypaI.com would generate two completely different keys.
It would mean that somewhere there is a common root, which if extracted, can derive all keys for all sites. Why introduce such a risk when there’s no reason to do that?
In both cases your device has a private key that it needs to secure. In my scenario we remove the third party cloud service.