frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Now Is the Best Time to Be a Duct Tape Engineer

https://derwiki.medium.com/now-is-the-best-time-to-be-a-duct-tape-engineer-eefc1d141c23
1•derwiki•1m ago•0 comments

'More harmful than helpful': young people sour on AI

https://www.ft.com/content/73fc962e-ce68-4521-9c5d-841a666eed10
1•1vuio0pswjnm7•2m ago•0 comments

Resourceful runner 'can race my own ghost' using homemade Meta Ray-Ban

https://www.tomshardware.com/peripherals/wearable-tech/resourceful-runner-can-race-my-own-ghost-u...
1•voxycon•2m ago•0 comments

The Art of Language

1•wronganswer•4m ago•1 comments

The job board hierarchy nobody talks about

https://get-sygnal.com/blog/job-board-hierarchy
1•caearac•5m ago•0 comments

Perfect randomness realised for the first time

https://ethz.ch/en/news-and-events/eth-news/news/2026/05/perfect-randomness-realised-for-the-firs...
1•wjSgoWPm5bWAhXB•6m ago•0 comments

His Chatbot Nearly Ruined Him. To Recover, He Had to Destroy It

https://www.wsj.com/tech/personal-tech/chatgpt-addiction-chatbots-recovery-7977308e
1•davidclark22•6m ago•0 comments

JIT Provisioning on Cloudflare Containers

https://waystones.cloud/journal/jit-provisioning-cloudflare-containers
2•Henrik716•8m ago•0 comments

Natural tissue immortality: Indefinite survival of sea cucumber explants

https://www.science.org/doi/10.1126/sciadv.aeb1394
2•hamburgererror•8m ago•0 comments

The Exclusive Retreat Where Wealthy Kids Learn How Not to Blow an Inheritance

https://www.wsj.com/lifestyle/careers/r360-novus-rich-kid-seminar-5cbb657a
2•thm•9m ago•0 comments

The Infosec Phrasebook

https://nesbitt.io/2026/06/01/the-infosec-phrasebook.html
2•progval•10m ago•0 comments

IEA: About Energy and AI

https://www.iea.org/reports/key-questions-on-energy-and-ai/executive-summary
2•samber•11m ago•0 comments

MiniMax debuts AI model built for long and complex coding tasks

https://www.scmp.com/tech/tech-trends/article/3355529/minimax-debuts-ai-model-built-long-and-comp...
2•thm•11m ago•0 comments

The software industry: annealing, but wrong

https://apenwarr.ca/log/20260531
3•Tomte•12m ago•0 comments

Say as many curse words as you can in 1 minute

https://rage-minute.lol/
2•driesdep•12m ago•0 comments

EtyML: a daily etymology puzzle built on word embeddings and BFS traversal

https://www.etyml.com/
2•ayushsanghavi•12m ago•0 comments

Verify your identity for Companies House

https://www.gov.uk/guidance/verify-your-identity-for-companies-house
2•sscaryterry•12m ago•1 comments

Web Search API Types: Three Architectures, One Confusing Name

https://www.newscatcherapi.com/blog-posts/web-search-api-types-2026
3•artembugara•14m ago•0 comments

Copilot usage metrics API adds cohorts for AI adoption

https://github.blog/changelog/2026-05-29-copilot-usage-metrics-api-adds-cohorts-for-ai-adoption/
2•saikatsg•19m ago•0 comments

Powerful A.I. Super PACs Duel over the Midterms: 'This Is a War'

https://www.nytimes.com/2026/05/30/us/politics/anthropic-openai-super-pacs-midterms.html
1•1vuio0pswjnm7•19m ago•0 comments

What It's Like to Be a Student at the First A.I.-Powered University

https://www.nytimes.com/2026/06/01/magazine/ai-university-college-california.html
1•reaperducer•19m ago•0 comments

AI Companies Don't Want Us to Be Token Efficient

https://prgrmmr.org/posts/ai-companies-dont-want-us-to-be-token-efficient/
3•magalhaesh•20m ago•0 comments

RemCTL: Reminders CLI for macOS

https://www.macstories.net/stories/introducing-remctl-the-power-user-reminders-cli-for-macos-and-...
1•defluct•20m ago•0 comments

Tencent to allow PayPal payments through its WeChat networks

https://apnews.com/article/china-tencent-paypal-tourists-economy-c871ddfb60aa87e9f1d6220c3131545d
1•geox•21m ago•0 comments

Scoped Error in Rust

https://kanru.info/scoped-error/
2•birdculture•21m ago•0 comments

AI was supposed to prevent downtime. Instead, it's creating new kinds of outages

https://www.fastcompany.com/91549985/ai-outages-splunk-report
3•1vuio0pswjnm7•22m ago•1 comments

Show HN: AbcGPT

https://twitter.com/iamtrask/status/2061288899238879290
1•williamtrask•22m ago•0 comments

AI debt sales reshape global corporate bond markets

https://www.reuters.com/business/finance/ai-debt-sales-reshape-global-corporate-bond-markets-2026...
2•1vuio0pswjnm7•24m ago•0 comments

Intel 8088s and non-Intel non-clones

https://dfarq.homeip.net/intel-8088s-and-non-intel-non-clones/
1•jnord•25m ago•0 comments

Storied Colors – a catalogue of named colors

https://storiedcolors.com/
1•susiecambria•26m ago•0 comments