The caveat is that we do need a key as long as the message (so we usually just repeat a keyword). In terms of strength, we have multiple ciphertext letters for each plaintext letter, one for each unique letter of the keyword so letter frequency information is obscured. However, not all knowledge of plaintext structure is lost.