frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•8mo ago

Comments

palata•8mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

A cosmic ring may challenge a key assumption about the universe

https://www.sciencenews.org/article/cosmic-ring-cosmology-principle
1•yusufaytas•1m ago•0 comments

How do I make $10k (What are you guys doing?)

1•b_mutea•1m ago•0 comments

The Trump Administration Admits More Ways DOGE Accessed Sensitive Personal Data

https://www.npr.org/2026/01/23/nx-s1-5684185/doge-data-social-security-privacy
1•backpackerBMW•2m ago•0 comments

Show HN: Carlton × CMP Signature AR NUME

https://github.com/Augmented-Reality-Virtual-Reality-AR-VR/Projects-in-AR-VR/pull/1
1•aroheir•5m ago•0 comments

The Inverse DevOps Principle

https://about.hannesortmeier.de/blog/inverse-devops-principle
1•sighansen•8m ago•0 comments

Major Canadian computer hardware online store compromised for months

https://old.reddit.com/r/bapccanada/comments/1qk4axy/canada_computers_online_card_skimmer/
1•bhouston•8m ago•1 comments

Hyundai Motor's Korean union warns of humanoid robot plan, sees threat to jobs

https://www.reuters.com/business/world-at-work/hyundai-motors-korean-union-warns-humanoid-robot-p...
1•tooltalk•10m ago•0 comments

A Management Philosopher with Heady Ideas About Beer (2009)

https://www.wsj.com/articles/SB125789690177942463
1•asplake•12m ago•0 comments

Show HN: Botnet of Ares – Hacking Simulator Open Playtest

1•tiniuclx•13m ago•0 comments

Show HN: ObsessionDB – We rebuilt ClickHouse infrastructure to cut our costs 50%

https://obsessiondb.com/
1•keks0r•14m ago•0 comments

Ask HN: What AI feature looked in demos and failed in real usage? Why?

2•kajolshah_bt•16m ago•1 comments

Ask HN: Anti-John the Baptist?

1•krautburglar•17m ago•0 comments

Show HN: Build agents via YAML with Prolog validation and 110 built-in tools

https://fabceolin.github.io/the_edge_agent/index.html
1•fabceolin•19m ago•0 comments

AI is not a NOT a horse (2023)

https://essays.georgestrakhov.com/ai-is-not-a-horse/
1•georgestrakhov•24m ago•0 comments

Partitioning a 17TB Table in PostgreSQL

https://www.tines.com/blog/futureproofing-tines-partitioning-a-17tb-table-in-postgresql/
1•shayonj•27m ago•0 comments

VS Code: Broken rendering on macOS after app resumed from idle state

https://github.com/microsoft/vscode/issues/284162
1•tosh•27m ago•0 comments

OpenAI Wants a Cut of Your Profits: Inside Its New Royalty-Based Plan

https://www.gizmochina.com/2026/01/21/openai-wants-a-cut-of-your-profits-inside-its-new-royalty-b...
1•thenaturalist•27m ago•0 comments

Shenzhou-20 Returns Safely After Historic In-Flight Debris Repairs

https://www.apollothirteen.com/article/orbital-resilience-shenzhou-20-returns-safely-following-hi...
1•darkmatternews•29m ago•0 comments

Alternatives to MinIO for single-node local S3

https://rmoff.net/2026/01/14/alternatives-to-minio-for-single-node-local-s3/
2•rymurr•29m ago•0 comments

Show HN: A verified foundation of mathematics in Coq (Theory of Systems)

1•Horsocrates•32m ago•0 comments

Heathrow's new scanners end dreaded rummage for liquids and laptops

https://www.reuters.com/world/heathrows-new-scanners-end-dreaded-rummage-liquids-laptops-2026-01-23/
1•comebhack•34m ago•0 comments

Can the prescription drug leucovorin treat autism? History says, probably not

https://www.npr.org/sections/shots-health-news/2026/01/22/nx-s1-5684294/leucovorin-autism-folic-f...
1•pseudolus•41m ago•0 comments

Davos Stops Pretending

https://messaging-custom-newsletters.nytimes.com/dynamic/render
1•doener•42m ago•2 comments

For the Children: A short story about the endgame of EU Chat Control

https://gigaprojects.online/post/1
2•giga_private•44m ago•1 comments

An Adversarial Coding Test

https://runjak.codes/posts/2026-01-21-adversarial-coding-test/
1•birdculture•45m ago•0 comments

Go Developer Survey 2025: How Gophers Use AI Tools, Editors, and Cloud Platforms

https://go.dev/blog/survey2025
1•Lwrless•45m ago•0 comments

Ask HN: What's the current best local/open speech-to-speech setup?

1•dsrtslnd23•47m ago•0 comments

A Multi-Entry Control Flow Graph Design Conundrum

https://bernsteinbear.com/blog/multiple-entry/
2•chunkles•50m ago•0 comments

Bernstein vs. United States

https://en.wikipedia.org/wiki/Bernstein_v._United_States
1•u1hcw9nx•52m ago•0 comments

Show HN: Workmux – Parallel development in tmux with Git worktrees

https://workmux.raine.dev/
1•rane•52m ago•0 comments