frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

A total solar eclipse will occur this summer. Everything you need to know

https://www.cnn.com/2026/06/06/science/total-solar-eclipse-path-august
1•tzury•6m ago•0 comments

An Absolutely Diabolical Phishing Email

https://twitter.com/thepatwalls/status/2060367488446017947
1•866-RON-0-FEZ•6m ago•0 comments

OpenCV 5.0 Released with Rewritten DNN Engine, Built-In LLM and VLM Support

https://www.phoronix.com/news/OpenCV-5.0-Released
1•daesorin•7m ago•0 comments

Ape: A New Vulkan Driver Written in the Zig Programming Language

https://www.phoronix.com/news/Vulkan-Ape-Driver
1•daesorin•8m ago•0 comments

Scientists Edit Human Embryo Genes with Startling Precision

https://www.nytimes.com/2026/06/04/science/embryos-gene-editing-crispr.html
1•birriel•9m ago•0 comments

Improving LM Studio's MLX Engine for Agentic Workflows

https://twitter.com/ostensiblyneil/status/2063006720616734835
1•tosh•12m ago•0 comments

There's a 137-Inch Bugatti TV Now, and It Folds

https://www.thedrive.com/news/theres-a-137-inch-bugatti-tv-now-and-it-folds
1•cf100clunk•13m ago•0 comments

Meshtastic Node Explained: Types, Range, Kits, and How to Choose the Best Setup

https://www.seeedstudio.com/blog/2026/03/17/meshtastic-node-guide/
2•RickJWagner•13m ago•2 comments

Computer Lessons

https://technicshistory.com/2026/06/06/computer-lessons/
1•cfmcdonald•16m ago•0 comments

Guardian 100 best novels (stats and errors)

https://mpaldridge.github.io/blog/guardian-novels.html
1•robin_reala•16m ago•0 comments

First Commodore PET sold, June 5, 1977

https://dfarq.homeip.net/first-commodore-pet-sold-june-5-1977/
3•erickhill•18m ago•0 comments

Show HN: Founder VC Horror Stories

https://rocketplace.org/stories
2•remarketme•18m ago•1 comments

K: Remarks on Style (1995) [pdf]

https://nsl.com/papers/style.pdf
1•tosh•19m ago•0 comments

Anthropic_API_key? Anthropic will bill your API account instead of your Max plan

https://old.reddit.com/r/ClaudeAI/comments/1tbaq2d/psa_if_your_project_has_an_anthropic_api_key_in/
2•behnamoh•21m ago•1 comments

DokuWiki Markdown Support

https://www.patreon.com/posts/dokuwiki-support-158080793
1•Tomte•23m ago•0 comments

Event Horizon – a Pihole Companion for non-technical network users

https://old.reddit.com/r/pihole/comments/1q25ekd/introducing_event_horizon_a_pihole_companion_for/
1•taubek•24m ago•0 comments

Reassemble

https://web.archive.org/web/20150311174405/https://web.stanford.edu/class/cs107/assign1.html
1•tosh•25m ago•0 comments

Show HN: How to do outpainting (canvas expansion) on an image [video]

https://www.youtube.com/watch?v=5Cq_grMKKj8
1•julienreszka•25m ago•0 comments

Restoring axon plasticity:chemogenetic activation saves autism-related behaviors

https://www.nature.com/articles/s41419-026-08873-0
2•bookofjoe•26m ago•0 comments

Rationales for Standards

https://www.thomas-huehn.com/rationales-for-standards/
2•Tomte•28m ago•0 comments

Baby botulism outbreak: FDA still doesn't know cause–or how to prevent it

https://arstechnica.com/health/2026/06/baby-botulism-outbreak-fda-still-doesnt-know-cause-or-how-...
1•Brajeshwar•29m ago•0 comments

Are Memories Transferable – Or Edible?

https://www.quantamagazine.org/are-memories-transferable-or-edible-20260605/
2•Brajeshwar•30m ago•0 comments

Show HN: Ccgs – Collaborative Claude Code sessions, stored in Git branches

https://github.com/ingram-technologies/claude-git-sessions
3•scrollaway•30m ago•0 comments

Protein name confusion created antibody mix-up affecting papers

https://www.science.org/content/article/protein-name-confusion-created-antibody-mix-affecting-hun...
2•Brajeshwar•30m ago•0 comments

Stealth Isn't Strategy: Post-Stealth Warfare a "Dirty Mix" of Humans and Robots

https://www.militarystrategymagazine.com/exclusives/stealth-isnt-strategy-post-stealth-warfare-wi...
2•anjel•33m ago•0 comments

Slopper GitHub Action: Fighting AI Slop Contributions on Open Source Projects

https://github.com/malvads/Slopper
1•malvads•36m ago•0 comments

You Can Run

https://magazine.atavist.com/2026/mccann-cocaine-fugitives
2•bryanrasmussen•39m ago•0 comments

The fourth law (on AI-generated supercustomized email marketing)

https://www.robinsloan.com/lab/fourth-law/
2•brandur•39m ago•0 comments

We have decided to make our service FREE. (Bloomberg Terminal for Everyone)

https://www.bullbear.ninja/notes/everything-free-ad-supported
2•haebom•40m ago•1 comments

Claudemux – Run and coordinate multiple Claude Codes reliably

https://github.com/wastedcode/claudemux
1•zeppelin_7•40m ago•1 comments