frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Replacing My ISP Router with a UniFi Cloud Gateway Max

https://kevquirk.com/replacing-my-isp-router-with-a-unifi-cloud-gateway-max
1•speckx•1m ago•0 comments

Codex-Maxxing

https://jxnl.co/writing/2026/05/10/codex-maxxing/
1•dnw•5m ago•0 comments

Product is not the problem. Your main image might be

https://www.getwhitebg.com
1•yibaoshan•5m ago•0 comments

SEC to Ready Plan for Trading Crypto Versions of Stocks

https://www.bloomberg.com/news/articles/2026-05-18/sec-is-said-to-ready-plan-for-trading-crypto-v...
2•petethomas•7m ago•0 comments

The first AI Bulk Upscaling tool for filmmakers and creator pipelines

https://upscalehero.com/
1•Ptconnection•11m ago•1 comments

Proposals Repo, a place for ideas to start their incubation journey

https://github.com/WICG/proposals
1•nashashmi•15m ago•0 comments

Balancing persistence vs. pivoting – is grit a virtue or wasteful?

https://optimizedbyotto.com/post/balancing-persistence-vs-pivoting/
1•MaxMussio•16m ago•0 comments

Formal proof that agentic AI governance latency can be O(1) instead of O(days)

https://arxiv.org/abs/2605.17909
1•riddhimohan•17m ago•0 comments

Ask HN: Company is rapidly cutting AI tool spend how to prep team?

2•Snakes3727•19m ago•6 comments

Show HN: Memory Concierge – hotel concierge AI

https://memory-concierge.vercel.app
1•abhilash617•20m ago•0 comments

Using algebra and LLMs to verify a flight-plan bug fix in Lean

https://jameshaydon.github.io/algebra-llms-lean-flight-plan/
1•jameshh•22m ago•0 comments

Show HN: Hsrs – Type-Safe Haskell Bindings Generator for Rust

https://github.com/harmont-dev/hsrs
2•suis_siva•23m ago•0 comments

Digital Growth Starts Here – Digital Marketing Agency

1•magicalweb•24m ago•0 comments

Apple Silicon costs LESS than OpenRouter

https://twitter.com/rohan_sood15/status/2056585919805714777
3•rohansood15•27m ago•0 comments

LLMCap – A proxy that hard-stops LLM API calls when you hit a dollar cap

https://www.llmcap.io/
1•cfaruk•32m ago•0 comments

Frontier models at open source cost – hot new AI Model Router

https://www.orcarouter.ai/
1•sangwen•34m ago•0 comments

Active Supply Chain Attack Compromises Antv Packages on NPM

https://socket.dev/blog/antv-packages-compromised
2•882542F3884314B•35m ago•0 comments

Finnish spy chief warns Europe may never break free from foreign tech

https://www.politico.eu/article/europe-tech-dependent-us-china-fully-sovereign-finnish-intel-chief/
4•giuliomagnifico•38m ago•1 comments

New Database Back End for WDQS

https://www.wikidata.org/wiki/Wikidata:SPARQL_query_service/WDQS_backend_update/Backend_Replacement
1•altilunium•39m ago•0 comments

Google, Blackstone to Create AI Cloud Firm with In-House Chips

https://www.bloomberg.com/news/articles/2026-05-19/google-to-create-ai-cloud-business-with-blacks...
2•htrp•45m ago•0 comments

Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital...
5•WarOnPrivacy•51m ago•0 comments

Bornagain.com

http://bornagain.com/
8•gregsadetsky•51m ago•2 comments

The Explore-Exploit Dilemma in Media Consumption (2016)

https://gwern.net/media-rl
1•mcmoor•54m ago•0 comments

Going Analog

https://www.natemeyvis.com/going-analog/
2•speckx•55m ago•0 comments

The Strange Rock Ship of Masuda

https://offbeatjapan.com/rock-ship-of-masuda/
1•thunderbong•59m ago•0 comments

Getting Confidence in (Agentic) Code

https://ucsd-cse-115-215.github.io/sp26/lectures/04-correctness.html
1•matt_d•1h ago•0 comments

A Quarter Century of Unix (Peter Salus, 1994)

https://archive.org/details/aquartercenturyofunixpeterh.salus_201910
1•ninjin•1h ago•1 comments

TuriX AI launched the latest version

https://github.com/TurixAI/TuriX-CUA
1•turixai•1h ago•1 comments

Open-sourcing ShipReq – a requirements platform written in FP Scala/Scala.js

https://gist.github.com/japgolly/538875580ec648ca7517ce04d63dc009
1•japgolly•1h ago•1 comments

Compute Optimal Tokenization: Scaling Laws for Data Compression in LLMs

https://co-tok.github.io/
1•matt_d•1h ago•0 comments