frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•6mo ago

Comments

palata•6mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Microsoft to remove WINS support after Windows Server 2025

https://www.bleepingcomputer.com/news/microsoft/microsoft-to-remove-wins-support-after-windows-se...
1•fleahunter•2m ago•0 comments

Intel Working on Linux Support for New Power Savings Feature with Xe3P_LPD

https://www.phoronix.com/news/Intel-Xe3P-LPD-System-Cache-FBC
1•doener•2m ago•0 comments

Essence and accident in language model-assisted coding

https://www.sicpers.info/2025/11/essence-and-accident-in-language-model-assisted-coding/
1•ingve•4m ago•0 comments

The Rise of the 'Just in Case' MRI

https://www.nytimes.com/2025/11/22/business/dealbook/full-body-mri.html
1•bookofjoe•5m ago•1 comments

Mental model to evaluate early-stage startups if join as first employee

https://www.bolshchikov.com/p/framework-to-assess-startup-potential
1•bolshchikov•5m ago•0 comments

OpenAI's House of Cards

https://www.thefp.com/p/niall-ferguson-the-ai-boom-is-a-house-of-cards
2•braza•8m ago•0 comments

Show HN: Ontology-driven knowledge graph extraction from text

1•cybermaggedon•15m ago•0 comments

The 35-year quest to bring Bach's lost organ works to light

https://www.theguardian.com/music/2025/nov/24/an-inner-duty-the-35-year-quest-to-bring-bachs-lost...
1•Archelaos•15m ago•0 comments

Progress Forum (For Progress Studies)

https://progressforum.org/posts/TEtG3iiutPA9HTwfE/about-us-and-faq
1•ronfriedhaber•21m ago•0 comments

Organisations can learn from the record fine over Capita's ransomware incident

https://doublepulsar.com/what-organisations-can-learn-from-the-record-breaking-fine-over-capitas-...
1•rwmj•23m ago•0 comments

Ntoh*/hton* is a bad API

https://purplesyringa.moe/blog/ntoh-hton-is-a-bad-api/
1•birdculture•24m ago•0 comments

Lovable's $6B Question: Where's the Moat?

https://old.reddit.com/r/lovable/comments/1p4mhup/lovables_6b_question_wheres_the_moat/
3•astonfred•25m ago•0 comments

Ask HN: What are some solutions for ensuring package security?

1•nhgiang•25m ago•0 comments

If 95% of generative AI pilots fail, what's going wrong?

https://leaddev.com/technical-direction/if-95-of-generative-ai-pilots-fail-whats-going-wrong
2•chhum•27m ago•1 comments

Ask HN: Best practice for using AI coding tools in a team?

1•boshenz•28m ago•0 comments

MIT Student Awed Top Economists with His AI Study Then It All Fell Apart

https://www.msn.com/en-us/money/careersandeducation/an-mit-student-awed-top-economists-with-his-a...
1•jnord•28m ago•0 comments

Rust-Analyzer Changelog #303

https://rust-analyzer.github.io//thisweek/2025/11/24/changelog-303.html
1•amalinovic•31m ago•0 comments

Round Robin: license that's share-alike for improvements and permissive for apps

https://roundrobinlicense.com/
1•cmitsakis•31m ago•0 comments

Contract signed for laser that can take out drones

https://www.bbc.com/news/articles/cr4345k05z3o
1•breve•33m ago•0 comments

QuantumSuperposition strongly-typed superpositions and quantum circuits for .NET

https://medium.com/@xhable/quantumsuperposition-multiverse-variables-and-quantum-circuits-in-c-75...
2•hutchpd•35m ago•1 comments

Show HN: Go Memory Visualizer, real-time struct layout and auto optimization

https://github.com/1rhino2/go-memory-visualizer
2•1rhino2•38m ago•0 comments

Show HN: Cruzes, a New Word Game

https://cruzes.io/
1•rpmoura•41m ago•0 comments

Bill Gates Foundation's 65% Microsoft Stock: Liquidity Play or a Cautious Signal

https://thinkmintmedia.blogspot.com/2025/11/87-billion-question-is-gates.html
1•iamtech•46m ago•0 comments

I put a real search engine into a Lambda, so you only pay when you search

https://nixiesearch.substack.com/p/i-put-a-real-search-engine-into-a
6•shutty•47m ago•0 comments

Thoughtleaderz by Jeff Czekaj

https://czekaj.com/thoughtleaderz.php
1•mankins•52m ago•0 comments

It's Called a Team for a Reason

https://www.codecabin.dev/post/its-called-a-team-for-a-reason
1•rebelchrisycom•52m ago•1 comments

Bookmarklet

https://blog.cloudflare.com/welcome-to-connectivity-cloud/
1•nyeinlay•52m ago•0 comments

No Backup, No Cry

https://world.hey.com/dhh/no-backup-no-cry-274e0c31
1•unripe_syntax•55m ago•0 comments

Show HN: Python UI-ME – Bringing life to Python functions

http://github.com/livetheoogway/python-uime
3•tusharnaik•57m ago•0 comments

OS Malevich – how we made a system that embodies the idea of simplicity (2017)

https://www.ajax-systems.uz/blog/hub-os-malevich-story/
1•frxx•57m ago•0 comments