frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•10mo ago

Comments

palata•10mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Prismo – Scrappy notes become a structured knowledge base you get quizzed on

https://prismo-app.com/
1•Elial•1m ago•1 comments

Get up to speed with partial clone and shallow clone (2020)

https://github.blog/open-source/git/get-up-to-speed-with-partial-clone-and-shallow-clone/
1•chmaynard•2m ago•0 comments

Yet Another UK HS2 Screw Up

https://www.bbc.co.uk/news/articles/czex3lj077xo
1•zabzonk•4m ago•0 comments

OpenChoreo: An open-source internal developer platform that does not hide K8s

https://openchoreo.dev/
1•hemapani•5m ago•1 comments

How I got a Dear ImGui App Approved on the Mac App Store

https://marchildmann.com/blog/imgui-mac-app-store/
1•hilti•6m ago•0 comments

LaGuardia Airport Closed After Runway Collision That Killed Two Pilots

https://www.wsj.com/us-news/faa-issues-ground-stop-at-laguardia-after-plane-collides-with-vehicle...
1•fortran77•7m ago•1 comments

Bypassing deep packet inspection with socat and HTTPS tunnels

https://blog.bofh.it/debian/id_472
1•speckx•8m ago•0 comments

The Truth About No-KYC Crypto Cards, from Someone Who Ran One

https://twitter.com/defyneric/status/2021116183898886201
1•gasull•9m ago•0 comments

Vertical Farms Tried to Compete with Open Field Farming. It Isn't Going Well

https://www.nytimes.com/2026/03/21/business/vertical-farms-tried-to-compete-with-open-field-farmi...
1•mistersquid•10m ago•0 comments

Lawmakers don't want VPNs to stand in the way of online age verification

https://www.theverge.com/column/898122/online-age-verification-vpns
1•gasull•15m ago•0 comments

OpenAI preps for IPO in 2026, says ChatGPT must be 'productivity tool'

https://www.cnbc.com/2026/03/17/openai-preps-for-ipo-in-2026-says-chatgpt-must-be-productivity-to...
2•speckx•16m ago•0 comments

Claude Opened the Straight of Hormuz

https://www.chinatalk.media/p/how-claude-opened-the-strait-of-hormuz
1•whalesalad•18m ago•0 comments

Bypassing all Active Directory password policies with one RPC call (with PoC)

https://simpity.eu/blog/ad-password-policies-security-theater
2•alexei-belous•18m ago•1 comments

Fullstack AI developer in 6 weeks (satire)

https://xcancel.com/gothburz/status/2035863431106953679
1•zbycz•18m ago•0 comments

On Claude Code

https://docs.google.com/document/d/e/2PACX-1vRycHNEW3R3iFolIaxUebTobuHWNOzXRbq-tKEy00uhrglFl1A0-E...
1•love2read•19m ago•0 comments

A Visual Guide to Attention Variants in Modern LLMs

https://magazine.sebastianraschka.com/p/visual-attention-variants
2•Brajeshwar•20m ago•0 comments

Formally Verifying the Easy Part

https://brainflow.substack.com/p/formally-verifying-the-easy-part
3•hnipps•21m ago•1 comments

The ancient reason there are 60 minutes in an hour

https://www.bbc.com/future/article/20260320-the-ancient-reason-there-are-60-minutes-in-an-hour-an...
2•ranit•24m ago•1 comments

Surface contamination holds the key to a static electricity mystery

https://physicsworld.com/a/surface-contamination-holds-the-key-to-a-static-electricity-mystery/
1•sohkamyung•24m ago•0 comments

What Came After the 486?

https://dfarq.homeip.net/what-came-after-486/
2•jnord•26m ago•0 comments

AI-Assisted Development: How to Code Faster Without Losing Control

https://medium.com/@coderai/ai-assisted-development-how-to-code-faster-without-losing-control-be8...
1•coderai•27m ago•0 comments

Show HN: Build your own Redactle Wikipedia list in one sentence

https://redactle.net/c
1•brikym•28m ago•1 comments

These coders want AI to take their jobs

https://www.vox.com/podcasts/483368/vibe-coding-ai-software-claude-codex-gemini-explained
1•gloxkiqcza•28m ago•0 comments

HogPocket – A mobile companion app for PostHog analytics

https://apps.apple.com/app/hogpocket/id6743059498
1•omardak•29m ago•0 comments

What America Could Learn from Asia's Robot Revolution

https://thereader.mitpress.mit.edu/what-america-could-learn-from-asias-robot-revolution/
1•sohkamyung•31m ago•0 comments

The Bay Area's animal welfare movement wants to recruit AI

https://www.technologyreview.com/2026/03/23/1134491/the-bay-areas-animal-welfare-movement-wants-t...
1•joozio•32m ago•0 comments

Award-winning bird recognition device

https://www.raspberrypi.com/news/award-winning-bird-recognition-device/
1•Brajeshwar•33m ago•0 comments

Cybersecurity Changes I Expect in 2026

https://danielmiessler.com/blog/cybersecurity-ai-changes-2026
1•speckx•33m ago•1 comments

Ads Are Popping Up on the Fridge and It Isn't Goong Well

https://www.wsj.com/lifestyle/samsung-refrigerator-ads-lg-whirlpool-ge-10ea7bcc
2•fortran77•36m ago•1 comments

Man generated songs with AI then had bots stream them to make over $8M

https://www.pcgamer.com/software/ai/man-pleads-guilty-to-generating-songs-with-ai-then-having-bot...
1•stared•36m ago•0 comments