frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•7mo ago

Comments

palata•7mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

How we used SubImage to fix React2Shell on our own infrastructure

https://www.subimage.io/blog/react2shell/
1•alexchantavy•2m ago•0 comments

New Linux platform will let you update your next car at home

https://www.zdnet.com/article/this-new-linux-platform-will-let-you-update-your-next-car-at-home-a...
1•CrankyBear•9m ago•0 comments

Paramount Makes Hostile Bid for Warner Bros. Discovery

https://www.nytimes.com/2025/12/08/business/paramount-warner-bros-discovery-netflix.html
1•doener•17m ago•1 comments

What Makes Goethe So Special?

https://www.newyorker.com/magazine/2025/12/08/goethe-a-life-in-ideas-matthew-bell-book-review
1•mitchbob•17m ago•1 comments

7-Eleven to Pay Record $4.5M Penalty for FTC Antitrust Order Violation Case

https://www.ftc.gov/news-events/news/press-releases/2025/12/7-eleven-pay-record-45-million-penalt...
1•gnabgib•18m ago•0 comments

The Lost Machine Automats and Self-Service Cafeterias of NYC (2023)

https://www.untappedcities.com/automats-cafeterias-nyc/
5•walterbell•19m ago•1 comments

Canadian traditional owners fear Australian-style LNG development

https://www.abc.net.au/news/2025-12-09/canada-traditional-owners-in-australia-to-protest-against-...
1•defrost•20m ago•0 comments

Scientific and Technical Amateur Radio

https://destevez.net/
5•gballan•20m ago•0 comments

Gig: How our 25G PON investment shatters the limits of today's internet

https://fiber.googleblog.com/2025/12/20-gig-update.html
1•xnx•22m ago•0 comments

Mr. Ren Zhengfei's Meeting with ICPC Foundation President

https://cence.comp.nus.edu.sg/cence/icpc_minutes_2025.html
2•doener•23m ago•0 comments

Metacode: The new standard for machine-readable comments for Python

https://github.com/pomponchik/metacode
1•pomponchik•24m ago•1 comments

Show HN: Octopii, a runtime for writing distributed applications in Rust

https://github.com/octopii-rs/octopii
1•puterbonga•25m ago•0 comments

RNA language models can generalize well on structure prediction tasks

https://www.nature.com/articles/s41467-025-60872-5
2•PaulHoule•29m ago•0 comments

Using an AI Mediator Because Humans Are Terrible at Conflict

https://www.mitigateapp.com/
2•mksinclair•32m ago•3 comments

Show HN: Tool to detect malware left behind after patching CVE-2025-55182

2•Just_Clive•38m ago•0 comments

Residents push back as 5G towers rise steps from their homes

https://www.local10.com/video/news/2025/12/04/residents-push-back-as-5g-towers-rise-steps-from-th...
3•walterbell•39m ago•0 comments

Using Citations to Explore Academic Literature

https://inciteful.xyz/
1•aragonite•41m ago•0 comments

What If Our Ancestors Didn't Feel Anything Like We Do?

https://www.theatlantic.com/magazine/2026/01/human-ancestors-emotion-history/684959/
2•petethomas•42m ago•1 comments

Authentication Explained: When to Use Basic, Bearer, OAuth2, JWT and SSO

https://javarevisited.substack.com/p/system-design-basics-authentication
3•rezaprima•43m ago•2 comments

Show HN: SteadyDancer – First-Frame Identity-Stable Dance Animation

https://www.steadydancer.net/?i=d1d5k
1•lu794377•44m ago•0 comments

Horses: AI progress is steady. Human equivalence is sudden

https://andyljones.com/posts/horses.html
4•pbui•44m ago•0 comments

I built an AI that learns code transformations from examples (not generative)

1•heavymemory•51m ago•0 comments

Bots, bias, and bunk: How can you tell what's real on the net?

https://www.theregister.com/2025/12/05/bots_bias_bunk/
1•CrankyBear•51m ago•0 comments

The Military Almost Got the Right to Repair. Lawmakers Just Took It Away

https://www.wired.com/story/the-military-almost-got-the-right-to-repair-lawmakers-just-took-it-away/
5•SanjayMehta•52m ago•0 comments

The Universal Weight Subspace Hypothesis

https://arxiv.org/abs/2512.05117
21•lukeplato•54m ago•3 comments

Trump Clears Sale of More Powerful Nvidia A.I. Chips to China

https://www.nytimes.com/2025/12/08/business/trump-nvidia-chips-china.html
4•aaraujo002•56m ago•1 comments

Nvidia Wins Trump's Approval to Sell H200 AI Chips in China

https://archive.is/wvnuG
1•wslh•57m ago•0 comments

Bringing More Real-Time News and Content to Meta AI

https://about.fb.com/news/2025/12/bringing-more-real-time-news-and-content-to-meta-ai/
1•donohoe•1h ago•0 comments

Manual: Spaces

https://type.today/en/journal/spaces
2•doener•1h ago•1 comments

Deprecation: Software Engineering at Google

https://abseil.io/resources/swe-book/html/ch15.html
3•jez•1h ago•0 comments