frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•11mo ago

Comments

palata•11mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Waymo's Robot Car Testing Ends in NYC After Permits Expire

https://www.thecity.nyc/2026/04/06/waymo-driverless-cars-testing-roads-autonomous-vehicle/
1•theahura•32s ago•0 comments

Hackers claim control over Venice San Marco anti-flood pumps

https://securityaffairs.com/190679/hacktivism/hackers-claim-control-over-venice-san-marco-anti-fl...
1•lschueller•1m ago•0 comments

Information Management: A Proposal (1989)

https://repository.cern/records/6kxvc-v6203
1•jruohonen•1m ago•0 comments

Acting Opportunities

1•mtrojlm•2m ago•0 comments

Writing Design Docs

https://blog.ceejbot.com/posts/design-docs/
1•ProfDreamer•3m ago•0 comments

OpenAI says to update Mac apps ChatGPT and Codex as security precaution

https://9to5mac.com/2026/04/10/openai-says-to-update-mac-apps-including-chatgpt-and-codex-as-secu...
1•lashull•4m ago•0 comments

Reconstruction of human metabolic models with large language models

https://www.pnas.org/doi/10.1073/pnas.2516511123
1•XzetaU8•4m ago•0 comments

Elixir Client SDK 1.0 for EventSourcingDB Now Available

https://docs.eventsourcingdb.io/blog/2026/04/13/elixir-client-sdk-10-now-available/
1•goloroden•4m ago•0 comments

I got tired of rearranging my monitors every time I plug them in

https://github.com/akshin18/monitor_man
1•akshin18•8m ago•0 comments

The Closing of the Frontier

https://tanyaverma.sh/2026/04/10/closing-of-the-frontier.html
1•MindGods•10m ago•0 comments

Apple removes Lebanese village names from Apple Maps as Israel attacks

https://twitter.com/EthanLevins2/status/2043366941922926940
21•newspaper1•12m ago•3 comments

Generate tool-specific AI config files from shared templates

https://github.com/fabis94/universal-ai-config
1•idid•14m ago•0 comments

LLM-Wiki

https://keepnotes.ai/blog/2026-04-12-llmwiki/
1•xngbuilds•16m ago•0 comments

Apple has removed most of the towns and villages in Lebanon from Apple maps

https://maps.apple.com/frame?center=33.723388%2C35.614698&span=1.983925%2C4.004193
96•thepasswordis•21m ago•32 comments

Why "200 OK" does not mean your system worked

https://blog.bridgexapi.io/why-200-ok-does-not-mean-your-system-worked
1•Bridgexapi•21m ago•0 comments

Y Combinator lets you cross the line [video]

https://www.youtube.com/watch?v=ptT_LGfT69k
2•ethanwillis•23m ago•0 comments

High schooler's 3D design saves Seminole County thousands on election equipment

https://www.clickorlando.com/news/local/2026/04/10/high-schoolers-3d-design-saves-seminole-county...
1•gnabgib•23m ago•0 comments

Agentjail: Minimal Linux sandbox for running untrusted code/apps/agents

https://github.com/bugthesystem/agentjail
1•ziyasal•23m ago•1 comments

Canal of the Pharaohs

https://en.wikipedia.org/wiki/Canal_of_the_Pharaohs
1•softwaredoug•23m ago•0 comments

Nailing Jell-O to the Wall, Again. Can China Contain LLMs?

https://senteguard.com/blog/nailing-jell-o-to-the-wall-again-can-china-contain-llms-1767694568878
1•paulpauper•23m ago•0 comments

Artificial Intelligence and Human Legal Reasoning

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6525800
1•paulpauper•23m ago•0 comments

Apps and programming: two accidental tyrannies

https://andymatuschak.org/tat/
1•nathcd•27m ago•0 comments

I build a modern APIs listing engine

https://api-engine.vercel.app/
2•heyFFFF•28m ago•1 comments

Show HN: I built a project board where AI agents join as real teammates

https://is.team
2•spotlayn•28m ago•0 comments

Every feature should earn its place

https://twitter.com/karrisaarinen/status/2043378194938777813
1•tosh•29m ago•0 comments

Drift. Native Mac ambient sound mixer with spatial audio (no subscription)

https://driftsound.app
2•beeruot•39m ago•0 comments

Can you self-host AI on Intel NPU or ARC (iGFX and proper card?

https://github.com/aweussom/NoLlama
1•aweussom•39m ago•1 comments

Apple Accused of Removing Village Names of Disputed Territory in South

https://twitter.com/Villgecrazylady/status/2043380336545968466
8•pain_perdu•41m ago•0 comments

Show HN: A proactive AI agent on iMessage that texts you before you even ask

https://hemesh.tech/builds/summer-ai.html
1•HemeshCh•42m ago•0 comments

IrDA

https://computer.rip/2026-04-11-IrDA.html
2•Sniffnoy•45m ago•1 comments