I don't get it. How does every device combo having a unique key pair help with security? They can all log in, right? So all you need is to compromise their session and you're in, whether they share the same passkey or not.
And if you're compromised in such a way that an attacker could steal your password then wouldn't they be able to just hijack your session instead?