frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•9mo ago

Comments

palata•9mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

New Library to build and deploy AI agents (the best I have seen in a long time)

https://github.com/teleonAI/teleon
1•karimbkh_•1m ago•1 comments

How to use Rain Sounds for sleeping?

https://rainsounds.xyz/how-to-use-rain-sounds-for-sleeping
1•mathnorth_com•1m ago•0 comments

Nexus State – Lightweight Atomic State Management for Modern Apps

https://jsdev.space/nexus-state-manager/
1•javatuts•2m ago•0 comments

Show HN: Our calendar is political, not mathematical – explore alternatives

https://calendar-architect.pages.dev
1•szemy2•4m ago•0 comments

Show HN: Fun Cricket 26 – 3 clicks to bowl, 3 to bat, 1000s of possibilities

https://cric26.fun
1•rockyj•5m ago•0 comments

Google Cloud APIs (gcloud CLI) seems to be down or broken

1•thej•5m ago•0 comments

Found a PSP Exploit but cant get to run a loader yet

1•kirito1337•5m ago•0 comments

Show HN: I made HappySRT to transcribe, translate, & summarize easily

https://www.happysrt.com/
1•Rizzist•7m ago•0 comments

Design Docs Considered Harmful

https://www.lucasfcosta.com/blog/design-docs
2•lucasfcosta•7m ago•0 comments

Show HN: TemplateFlow – Build AI workflows, not prompts

https://github.com/heyaohuo/TemplateFlow
1•yaohuo•7m ago•0 comments

Show HN: Searchable aggregator of 24M London council spending transactions

https://cspend.uk
2•ashfn•9m ago•1 comments

Why AI Models Fail at Iterative Reasoning and What Could Fix It

https://medium.com/@contact.n8n410/why-ai-models-fail-at-iterative-reasoning-51f8f9930625
1•solscan_dev•10m ago•0 comments

The Missing Sidebar in Cursor

https://morningcoffee.io/git-compare
1•shiroyasha•11m ago•0 comments

I built Google Bigtable in Go. Single file, zero dependencies

https://jitesh117.github.io/blog/implementing-google-bigtable-in-golang/
2•Jitesh117•12m ago•0 comments

Why Developers Keep Choosing Claude over Every Other AI

https://www.bhusalmanish.com.np/blog/posts/why-claude-wins-coding.html
1•okchildhood•12m ago•0 comments

Show HN: NostalgiApp – Native macOS launcher for 7k+ DOS games (eXoDOS)

1•mmsols•15m ago•0 comments

What the coming era of highly bespoke software might look like

https://twitter.com/karpathy/status/2024583544157458452
1•stared•16m ago•0 comments

Ask HN: How to measure how much data one can effectively process or understand?

6•mbuda•17m ago•1 comments

A Brief History of the Creator of C++: Bjarne Stroustrup (video)

https://www.youtube.com/watch?v=uDtvEsv730Y
1•michelangelo•19m ago•0 comments

I'm Sick of This AI Shit [video]

https://www.youtube.com/watch?v=7XGct4rbYfI
1•thm•20m ago•0 comments

Show HN: Legal RAG Bench

https://isaacus.com/blog/legal-rag-bench
2•beowa•21m ago•0 comments

Mrhbaan Syria Fedora Linux Now Available in Syria

https://fedoramagazine.org/fedora-syria/
1•_sofar•22m ago•0 comments

AWS Security Best Practices: Proven Strategies for 2026

https://www.kellton.com/kellton-tech-blog/aws-security-best-practices
1•Priyasinhakt•23m ago•0 comments

Personal Blog Should Have Comments

https://medv.io/blog/your-personal-blog-should-have-comments
1•medv•24m ago•0 comments

The moat has moved: Software used to be expensive to build

https://designexplained.substack.com/p/the-moat-has-moved
1•kaizenb•25m ago•0 comments

Show HN: OpenClaw Assistant – Android voice assistant app for OpenClaw

https://github.com/yuga-hashimoto/openclaw-assistant
1•YugaHashimoto•25m ago•0 comments

Show HN: Doksnet – keep docs and code in sync with hash verification

1•pulko•25m ago•0 comments

Erxi or how I learned to love the fast testing suite

https://hahn.website/blog/erxi/
1•t_null•27m ago•0 comments

Silicon Valley engineers were indicted for allegedly sending secrets to Iran

https://www.cnbc.com/2026/02/20/three-engineers-charged-stealing-google-trade-secrets-data-iran-s...
1•giuliomagnifico•28m ago•0 comments

Reproducing Anthropic's "Counting Manifold"

https://huggingface.co/spaces/t-tech/manifolds
3•ummagumm_a•29m ago•2 comments