frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•6mo ago

Comments

palata•6mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Rep+: Fast AI-Powered HTTP Repeater in Chrome

https://github.com/bscript/rep
1•bscript•43s ago•1 comments

Peekaping – self-hosted uptime monitoring, in Go

https://peekaping.com/
1•hectormalot•51s ago•0 comments

A Tour of Aquarius Reef Base (2015) [video]

https://www.youtube.com/watch?v=v3qqO8yQswg
1•jstanley•2m ago•0 comments

OpenAI's Changes Sent Some Users Spiraling

https://www.nytimes.com/video/technology/100000010535987/how-openais-changes-sent-some-users-spir...
1•fleahunter•3m ago•0 comments

Show HN: Whistle – Offline, private voice transcription using whisper

https://play.google.com/store/apps/details?id=com.blazingbanana.whistle&hl=en_US
1•blazingbanana•3m ago•0 comments

Menghubungi CS Indodax

1•kamuapatme•4m ago•0 comments

Experimenting with Robin Hood Hashing

https://twdev.blog/2025/11/robin_hood/
1•signa11•4m ago•0 comments

Tips Menghubungi CS Ajaib

1•kamuapatme•5m ago•0 comments

Introducing The Flux Keyboard

https://fluxkeyboard.com/?v=0b3b97fa6688
1•signa11•5m ago•0 comments

RavynOS: Open-Source macOS with Same BSD Pedigree

https://hackaday.com/2025/11/22/ravynos-open-source-macos-with-same-bsd-pedigree/
1•adamretter•9m ago•0 comments

The Rise of Agentic AI in 2025: Autonomous Agents

https://paidforarticles.in/top-news-the-rise-of-agentic-ai-in-2025-why-autonomous-agents-are-fina...
1•iamtech•12m ago•0 comments

Tell HN: MS's integration of OneDrive into Windows is a total mess

1•retube•15m ago•0 comments

Customer Service Garuda Indonesia

1•GardaTerdepan•16m ago•11 comments

The carbon cost of reality TV shows like The Traitors

https://theconversation.com/the-hidden-carbon-cost-of-reality-tv-shows-like-the-traitors-269675
1•zeristor•17m ago•0 comments

Devs (TV Series)

https://en.wikipedia.org/wiki/Devs_(TV_series)
2•nikolay•21m ago•1 comments

A Camera of Miroslav Tichý

https://artblart.com/tag/a-camera-of-miroslav-tichy/
1•Kaibeezy•32m ago•0 comments

Picky – A Judgemental Trashcan Robot

https://www.creativeapplications.net/member/picky-a-judgemental-trashcan-robot/
1•bryanrasmussen•35m ago•1 comments

What a chatbot thinks about Meta (reader discretion advised)

https://viewreplyy.com/share/galactico/4w1b485
1•galactic_atom•47m ago•0 comments

LLM Council: query multiple LLMs, and asks them to rank each other's work

https://github.com/karpathy/llm-council
1•maxloh•48m ago•0 comments

Ask HN: What browser do you use?

1•whatever3•49m ago•0 comments

Abstracting cloud infra software from vendor hardware with K8s

https://runos.com/blog/why-we-built-runos.html
1•didierbreedt•51m ago•0 comments

20x Faster TRL Fine-Tuning with RapidFire AI

https://huggingface.co/blog/rapidfireai
1•ibobev•56m ago•0 comments

NaTex: Seamless Texture Generation as Latent Color Diffusion

https://natex-ldm.github.io/
2•GaggiX•1h ago•0 comments

Gemini 3 Just Made Larry Page World's Third Richest Man

https://vechron.com/2025/11/larry-page-overtakes-jeff-bezos-to-become-third-richest/
13•GeorgeWoff25•1h ago•0 comments

GitHub have added social logins

https://github.com/signup
2•aiiizzz•1h ago•2 comments

Julia for Microcontrollers and Embedded Environments

https://joel.id/julia-my-love/
2•wagerlabs•1h ago•1 comments

Lex Fridman Podcast: Truth, Science, and Censorship in a Pandemic (2021) [video]

https://www.youtube.com/watch?v=TG6BuSjwP4o
1•g42gregory•1h ago•0 comments

Letter from Codeberg: Onwards and Upwards

https://blog.codeberg.org/letter-from-codeberg-onwards-and-upwards.html
1•birdculture•1h ago•1 comments

Parallel Threads in Racket v9.0

https://blog.racket-lang.org/2025/11/parallel-threads.html
2•Bogdanp•1h ago•0 comments

Show HN: Share Kindle Scribe Notebooks to Cloud Storage

https://docgenie.co.uk
1•qwikhost•1h ago•0 comments