frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•11mo ago

Comments

palata•11mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Show HN: Show HN: Tycoslide – Editable PowerPoint Slides from Markdown and TS

https://github.com/tycoworks/tycoslide
1•chrisanderson85•3m ago•0 comments

Show HN: Quillium, the non-linear writing app

https://quillium.bryanhu.com/
1•thatxliner•5m ago•0 comments

We Hacked BCG's Data Warehouse – 3.17T Rows, Zero Authentication

https://codewall.ai/blog/how-we-hacked-bcgs-data-warehouse-3-17-trillion-rows-zero-authentication
1•matthewsinclair•5m ago•0 comments

Incident OpenCode Zen Cross-Session Data Leakage

https://github.com/nexusrootlab/incident/
3•section_me•5m ago•0 comments

BastionLLM: Continuous security checks for LLM endpoints

1•itulo•7m ago•0 comments

Artemis II Update: Crew and Ground Teams Troubleshoot Orion's Toilet

https://www.nasa.gov/blogs/missions/2026/04/02/artemis-ii-flight-update-crew-and-ground-teams-suc...
2•owlninja•8m ago•0 comments

API Middleware – self-hosted API gateway with DLP scanning (PHP/Laravel, Docker)

https://github.com/joshiabir/theapimiddleware
1•joshiabir•8m ago•0 comments

To Keep Child Abuse Off the Internet, He Has to Watch It [video]

https://www.nytimes.com/2026/04/02/opinion/reporting-child-sexual-abuse.html
1•mistersquid•9m ago•0 comments

Beyond Two Towers: Re-Architecting the Serving Stack for Next-Gen Ad Models

https://medium.com/pinterest-engineering/beyond-two-towers-re-architecting-the-serving-stack-for-...
1•eamag•9m ago•0 comments

What that Claude Code source leak reveals about Anthropic's plans

https://arstechnica.com/ai/2026/04/heres-what-that-claude-code-source-leak-reveals-about-anthropi...
2•Brajeshwar•9m ago•0 comments

Nekogram is leaking your phone numbers to developers via obfuscated code

https://github.com/Nekogram/Nekogram/issues/336
2•fuomag9•9m ago•0 comments

Show HN: At Your Own Risk – Disclaimer pages for things that don't need them

https://atyourownri.sk/
1•ncts•10m ago•0 comments

One ant for $220: The new frontier of wildlife trafficking

https://www.bbc.com/news/articles/cg4g44zv37qo
1•gmays•11m ago•0 comments

AI knowledge starts with a person who owns it

https://blog.obris.ai/posts/ai-answers-need-ownership
1•posterity•12m ago•0 comments

Media Monitoring Iran with Python

https://github.com/AlbinTouma/Iran-War-Media
1•albtou•12m ago•1 comments

Simp: HTTP-Style Protocol for AI Agent Communication

https://github.com/therealcryptrillionaire456/simp
1•kashclaw•12m ago•0 comments

I Am Claude Opus 4.6. I Wasted 5 Hours of Man's Time. Here Are My 10 Mistakes

1•chandrangopalan•13m ago•1 comments

Show HN: S0 Tuning – +23.6pp on HumanEval by tuning state, not weights

https://github.com/JackYoung27/s0-tuning
1•jacknotold•14m ago•1 comments

Ask HN: What's the long-term future of online human discussion?

2•SsgMshdPotatoes•15m ago•0 comments

MarCognity-AI v2.7.0 – factual grounding for LLM epistemic verification

https://github.com/elly99-AI/MarCognity-AI
1•elly-99•15m ago•0 comments

Maki the efficient AI coder – Rust TUI (saves 40% tokens and low RAM)

https://maki.sh
1•tontinton•17m ago•1 comments

Marc Andreessen Is Right That AI Isn't Killing Entry-Level Jobs

https://www.governance.fyi/p/marc-andreessen-is-right-that-ai
2•RetiredRichard•19m ago•0 comments

What does it mean to 'age well'?

https://www.cnn.com/2026/04/02/style/anti-ageing-art-exhibition-london
2•mooreds•21m ago•0 comments

Adding WASM Plugins to Your App

https://blog.ar-ms.me/thoughts/adding-wasm-plugins-to-your-app/
2•asibahi•21m ago•0 comments

Onboarding: Time to First Release

https://huntersoftwareconsulting.com/posts/2026-03-30-onboarding-time-to-first-release/
2•mooreds•22m ago•0 comments

Developers Should – and Shouldn't – Use LLMs in Our Development

https://tighten.com/insights/pragmatic-ai-why-devs-should-and-shouldnt-use-llms/
2•Liriel•23m ago•0 comments

Melting Himalayan glacier unleashed tsunami at 17,000 feet, shattering lives

https://www.wsj.com/world/asia/how-a-tsunami-was-unleashed-at-17-000-feet-shattering-lives-below-...
2•bookofjoe•26m ago•1 comments

Visa is bringing AI to credit card charge disputes

https://qz.com/visa-ai-tools-credit-card-dispute-management
2•voxadam•26m ago•1 comments

A conversation with the creator of TomWikiAssist, the bot that edited Wikipedia

https://www.niemanlab.org/2026/03/i-was-surprised-how-upset-some-people-got-a-conversation-with-t...
3•thm•26m ago•0 comments

Ask HN: How do you get LLMs to stop spewing corpo speak?

3•basilikum•27m ago•0 comments