frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•10mo ago

Comments

palata•10mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

A Day in the Life of an Enshittificator [video]

https://www.youtube.com/watch?v=T4Upf_B9RLQ
1•leephillips•48s ago•0 comments

64-bit Hurd support added to GNU Guix

https://guix.gnu.org/en/blog/2026/the-64-bit-hurd/
1•delotrag•49s ago•0 comments

Show HN: I Am Building Web App's for Vintage Computers and Browsers

1•knownlimitation•1m ago•0 comments

Show HN: OpenTypeless – open-source AI voice input that types into any app

https://github.com/tover0314-w/opentypeless
2•tover0314•4m ago•1 comments

Beabox: Native UI for Beads

https://github.com/beadbox/beadbox
1•beadbox•4m ago•0 comments

Is AI killing people by accident?

https://garymarcus.substack.com/p/is-ai-already-killing-people-by-accident
1•starkparker•5m ago•0 comments

Show HN: Pydantypes – The missing Pydantic types for cloud, DevOps, AI

https://github.com/oborchers/pydantypes
1•theroot_•7m ago•0 comments

Show HN: Orb Platform – 3 content APIs for AI agents that teach

https://word-orb-api.nicoletterankin.workers.dev/playground
1•dailylesson•7m ago•0 comments

Show HN: RewardHackWatch – Reward hacking detector for LLM agents

https://github.com/aerosta/rewardhackwatch
1•aerosta•8m ago•1 comments

You're Not an Architect Anymore: The New Role of the Builder in 2026

https://medium.com/@DavidLiCause/youre-not-an-architect-anymore-the-new-role-of-the-builder-in-20...
1•davidlicause•9m ago•0 comments

Show HN: Catatonica – an app that measures stillness, not productivity

https://catatonica.pages.dev
1•Prince-Gabriel•11m ago•0 comments

Rocks and Sand (capacity planning on Postgres)

https://www.enterprisedb.com/blog/rocks-and-sand
1•b-man•11m ago•0 comments

Show HN: Bonetflix – View IMDB and Filmaffinity Ratings on Netflix

https://bonetflix.com/
1•kujaomega•13m ago•0 comments

Show HN: Business in a Box – ~one-shot a typical startup

https://github.com/dylandrop/business-in-a-box
2•dylandrop•15m ago•0 comments

Mythical Agent-Month

https://wesmckinney.com/blog/mythical-agent-month/
1•0xcafefood•15m ago•0 comments

The Amish Paradox (2004)

https://www.latimes.com/archives/la-xpm-2004-jan-12-he-amish12-story.html
1•paulpauper•17m ago•0 comments

You're a Computer Science Major. Don't Panic About A.I

https://www.nytimes.com/2025/11/12/opinion/ai-coding-computer-science.html
2•paulpauper•19m ago•1 comments

The Sunday Signal: The Loom, the Layoff, and the Life Raft

https://newsletter.djr.ai/p/the-sunday-signal-the-loom-the-layoff
1•discoinferno•19m ago•0 comments

The Great Online Game (2021)

https://www.notboring.co/p/the-great-online-game
1•simonebrunozzi•19m ago•0 comments

Thanks for Subscribing

https://www.fsf.org/free-software-supporter/success
1•maing•20m ago•0 comments

Show HN: Open-source MCP server for AI podcast clipping

https://github.com/nmbrthirteen/podcli
1•nsiradze•21m ago•0 comments

GNU Hurd on Guix Is Ready with 64-Bit Support, SMP Multiprocessor Support "Soon"

https://www.phoronix.com/news/GNU-Hurd-64-bit-2026
3•voxadam•21m ago•0 comments

OpenAI's DoD contract may allow mass surveillance and autonomous weapons

https://drew337494.substack.com/p/perfectly-transparent
4•fwipsy•22m ago•1 comments

'Employers are increasingly turning to degree and GPA'

https://fortune.com/2026/01/06/recruiting-college-isnt-dead-top-schools-not-talent-is-everywhere/
6•paulpauper•23m ago•1 comments

Math Academy Review: The Shoe-Tying Method Behind Adaptive Math Learning

https://opened.co/blog/math-academy-review-shoe-tying-method
2•gmays•26m ago•0 comments

Background Jobs for TanStack Start with pg-boss

https://jxd.dev/writing/background-jobs-tanstack-start-pg-boss/
1•jamie_davenport•27m ago•0 comments

Power Mode Plugin for Neovim (2026 Take)

https://github.com/axsaucedo/neovim-power-mode
1•axsaucedo•28m ago•1 comments

Claude dethrones ChatGPT as top U.S. app after Pentagon saga

https://www.axios.com/2026/03/01/anthropic-claude-chatgpt-app-downloads-pentagon
5•doener•28m ago•0 comments

The unreasonable effectiveness of S-Expressions

https://nim-lang.org/araq/sexpressions.html
2•moigagoo•30m ago•0 comments

Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions

https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
1•pluc•32m ago•0 comments