frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Ask HN: Does your mind drift while waiting for AI prompts to finish?

1•cryptoSympozium•3m ago•1 comments

The MRV engine for carbon removal

https://www.cula.tech/
1•doener•3m ago•0 comments

Against essential and accidental complexity (2020)

https://danluu.com/essential-complexity/
1•pramodbiligiri•3m ago•0 comments

Magnetically Hovering Guitar Strings

https://www.youtube.com/watch?v=ueCO4spGNPs
1•SweetSoftPillow•3m ago•0 comments

Ask HN: How much we change since LLM era?

1•modinfo•6m ago•0 comments

Dear Pinboard, I'm breaking up with you. It's me and it's you

https://michaelharley.net/posts/2026/06/16/dear-pinboard-im-breaking-up-with-you-its-me-and-its-you/
1•shaunpud•6m ago•0 comments

The Internet Isn't in the Cloud. It's on the Ocean Floor

https://axisbrief.substack.com/p/the-internet-isnt-in-the-cloud-its
1•Axis_Brief•6m ago•0 comments

Google: The New SDLC with Vibe Coding (2026)

https://www.kaggle.com/whitepaper-the-new-SDLC-with-vibe-coding
1•kubik369•10m ago•0 comments

W Social, Public Institutions and the Theater of European Digital Sovereignty

https://blog.elenarossini.com/w-social-public-institutions-and-the-theater-of-european-digital-so...
1•rapnie•10m ago•0 comments

Mastra NPM Supply Chain Attack: 140 Packages Backdoor via easy-day-JS Typosquat

https://www.stepsecurity.io/blog/mastra-npm-packages-compromised-using-easy-day-js
1•shaunpud•11m ago•0 comments

Show HN: OpenTalk2HTML – Convert video meeting transcripts to readable HTML

https://github.com/Aimino-Tech/opentalk2html
1•xducn1•13m ago•0 comments

AI Scenarios 2030: Helping policymakers plan for the future of AI

https://www.gov.uk/government/publications/ai-scenarios-2030-helping-policymakers-plan-for-the-fu...
1•hunglee2•14m ago•0 comments

The (Fake) Long Decline of Fertility

https://lymanstone.substack.com/p/the-fake-long-decline-of-fertility
1•barry-cotter•14m ago•0 comments

Show HN: Noema64 – an open-source LLM chess engine (still in beta though)

https://github.com/ahmeddyounis/noema64
1•ahmed_duski•16m ago•1 comments

Pipkin's Light Bulb Moment

https://spark.iop.org/pipkins-light-bulb-moment
1•redbell•16m ago•0 comments

SwissJURA3D – 3D geological model of the Swiss Jura

https://www.swisstopo.admin.ch/en/jura3d-en
1•bschne•18m ago•0 comments

AI Made Internal Tools Easy to Build. Keeping Them Alive Is the Hard Part

https://www.dforge.io/blog/internal-tools-built-to-last
1•andreypt•19m ago•0 comments

Chrome Extensions: The Hidden Risks No One Talks About and How to Stay Safe

https://old.reddit.com/r/AgentContext_dev/comments/1u862iu/chrome_extensions_the_hidden_risks_no_...
1•javaeeeee•21m ago•0 comments

Nanowar of Steel – Kotlin (Official Power Point Video)

https://www.youtube.com/watch?v=BsfXZjKLT9A
2•thinker5555•22m ago•0 comments

Show HN: Open-Source RAG Security Kit for Zero-Trust Retrieval

https://blog.aetherguard.ai/building-a-zero-trust-security-layer-for-rag-pipelines
1•aamir_m•22m ago•0 comments

Engineering vs. Software

https://crackedbeefcake.com/on/engineering/
1•lazerjesus•24m ago•0 comments

A tale of two path separators

https://alexwlchan.net/2021/slashes/
1•dbaupp•25m ago•0 comments

How many Americans are using AI – and how?

https://usafacts.org/articles/how-many-americans-are-using-ai-and-how/
1•giuliomagnifico•26m ago•0 comments

Half-Life 2 RTX has shrunk from 80 GB to 50 GB

https://www.nvidia.com/en-gb/geforce/news/rtx-remix-agent-skills-update/
2•HelloUsername•27m ago•0 comments

Can you self host an open source productivity suite in 2026?

https://medium.com/tech-stackups/is-it-feasible-to-self-host-an-open-source-eu-sovereign-producti...
1•ritzaco•28m ago•0 comments

The State of Fable, the Jailbreak Problem, SpaceX Acquires Cursor

https://stratechery.com/2026/the-state-of-fable-the-jailbreak-problem-spacex-acquires-cursor/
2•swolpers•34m ago•0 comments

Genesis AI launches Eno general-purpose robot

https://www.therobotreport.com/genesis-ai-launches-eno-general-purpose-robot/
1•vinodstartup•35m ago•0 comments

AI Cyber Tools Move into a New Phase as Governments Tighten Control

https://freedomforallamericans.org/ai-cyber-tools-government-control/
1•aledevv•35m ago•0 comments

Dumbnote – fast Markdown note app

https://dumbnote.app
3•amai•37m ago•0 comments

People are abandoning news sites for social media

https://www.niemanlab.org/2026/06/news-sites-are-the-new-newspapers-people-are-abandoning-them-fo...
5•giuliomagnifico•37m ago•0 comments