frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•8mo ago

Comments

palata•8mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Two empty chairs: why "obvious" decisions keep breaking production

https://read.perspectiveship.com/p/perspective-taking
1•birdculture•36s ago•0 comments

Things got too easy with AI

https://gusarich.com/blog/things-got-too-easy
1•Gusarich•1m ago•0 comments

Glass Core Substrates and Glass Interposers: Advanced Packaging for AI and HPC

https://www.microwavejournal.com/articles/44910-glass-core-substrates-and-glass-interposers-new-g...
1•teleforce•2m ago•0 comments

What happens to the human body in 49C heat? Australians are finding out

https://www.theguardian.com/australia-news/2026/jan/27/what-happens-to-the-human-body-in-49c-heat...
1•beardyw•2m ago•0 comments

Voice-first dating app that matches you in 4 days

https://voicevibe.dating/
1•evercrestaimee•3m ago•1 comments

Bop Spotter

https://walzr.com/bop-spotter
1•mattmark•5m ago•1 comments

South Korea's Edenlux set for U.S. debut of eyestrain wellness device

https://techcrunch.com/2026/01/26/south-koreas-edenlux-set-for-u-s-debut-of-eye-strain-wellness-d...
2•plun9•8m ago•0 comments

Automating Image Compression

https://www.ramijames.com/thoughts/on-automating-image-compression
8•ramijames•10m ago•0 comments

Shorlabs: Deploy back ends without the hassle. (OSS Alternative to Render)

https://www.shorlabs.com/
10•shorlabss•10m ago•0 comments

Ask HN: What's your favorite self-hosted application?

1•surrTurr•13m ago•0 comments

Ask HN: What is the hair on fire problem in your company?

2•nemath•18m ago•0 comments

Trump's $6T crypto plot [video]

https://www.youtube.com/watch?v=hqNxmWYMAr4
2•simonebrunozzi•22m ago•0 comments

Summary of CVE-2026-23864

https://vercel.com/changelog/summary-of-cve-2026-23864
1•tamnd•23m ago•0 comments

Show HN: Externalized Properties, a modern Java configuration library

https://github.com/joel-jeremy/externalized-properties
1•jeyjeyemem•25m ago•0 comments

Collatz High Cycles Do Not Exist (K. Knight), Discrete Mathematics 349(3), 2023

https://hal.science/hal-04261183/document
1•vismit2000•25m ago•0 comments

Show HN: GetClawdbot – A Community Guide and Skill Hub for Clawdbot

https://getclawdbot.org
1•medivhX•28m ago•1 comments

Chanfana: OpenAPI 3.1 and Zod for Hono/itty-router on Cloudflare Workers

https://github.com/cloudflare/chanfana
1•Lwrless•30m ago•0 comments

Syncthing: Open-Source Continuous File Synchronization

https://github.com/syncthing/syncthing
1•AbuAssar•31m ago•0 comments

Nixtamal: Fulfilling, Pure Input Pinning for Nix

https://nixtamal.toast.al
2•toastal•33m ago•0 comments

Microsoft ordered to stop tracking school children

https://noyb.eu/en/noyb-win-microsoft-ordered-stop-tracking-school-children
2•HotGarbage•34m ago•0 comments

Ask HN: What's your wiring pattern for large addressable LED installs?

3•emmasuntech•35m ago•1 comments

The state of Linux music players in 2026

https://crescentro.se/posts/linux-music-players-2026/
3•signa11•36m ago•0 comments

Disabling GitHub MCP on CC extended my sessions ~10%

https://staunch.ai/blog/disabling-github-mcp
1•irasigman•38m ago•0 comments

EU-India Free Trade,Investment Protection and Geographical Indications Agreement

https://policy.trade.ec.europa.eu/eu-trade-relationships-country-and-region/countries-and-regions...
3•Someone•38m ago•1 comments

DeepSeek-OCR 2

https://github.com/deepseek-ai/DeepSeek-OCR-2
3•wahnfrieden•39m ago•0 comments

From Hours to Seconds: Automating Python Security with AI?

https://nocomplexity.substack.com/p/from-hours-to-seconds-automating
1•runningmike•40m ago•0 comments

How do you use LLMs to verify databases with minimal hallucinations?

1•rochansinha•41m ago•0 comments

Windows Central Eliminates Most of Its Gaming Journalists

https://80.lv/articles/windows-central-eliminates-most-of-its-gaming-journalists
2•pjmlp•41m ago•0 comments

Anthropic launches the MCP Apps open spec, in Claude.ai

https://www.latent.space/p/ainews-anthropic-launches-the-mcp
2•swyx•42m ago•0 comments

Ask HN: What Happened to Apple App Clips?

4•tomtec•46m ago•5 comments