frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•7mo ago

Comments

palata•7mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Update on my journey toward the Rust compiler team

https://old.reddit.com/r/rust/comments/1pw5i9y/4_months_later_update_on_my_journey_toward_the/
1•nhatcher•42s ago•1 comments

Google is letting users swap out Gmail addresses without losing their data

https://www.latimes.com/business/story/2025-12-26/google-will-let-users-swap-out-gmail-addresses-...
1•not4uffin•2m ago•0 comments

NyroDB – Universal rust database engine, model based, fast

https://github.com/TheRemyyy/nyro-db
1•TheRemyyy•3m ago•1 comments

Tourism Crisis Hits the United States in 2025 as International Visitor Plunge

https://www.travelandtourworld.com/news/article/tourism-crisis-hits-the-united-states-in-2025-as-...
1•mindracer•6m ago•0 comments

You can't design software you don't work on

https://www.seangoedecke.com/you-cant-design-software-you-dont-work-on/
1•todsacerdoti•7m ago•0 comments

What condition one in Antarctica looks like [video]

https://www.youtube.com/shorts/Cq7GB1vp5dw
1•keepamovin•8m ago•0 comments

Aged care centre confronts racism with cultural celebrations

https://www.abc.net.au/news/2025-12-25/aged-care-centre-starts-cultural-celebrations-to-address-r...
1•Tomte•8m ago•0 comments

Claude Code Auto Improve

https://github.com/Polandia94/auto-improvement
1•polandia94•12m ago•1 comments

Hanuman Chalisa English

https://hanuman-chalisa-bhajan.blogspot.com/2010/01/shri-hanuman-chalisa-english.html
1•janebush08•16m ago•0 comments

Rilmenidine extends lifespan and healthspan in Caenorhabditis elegans

https://onlinelibrary.wiley.com/doi/10.1111/acel.13774
2•manidoraisamy•23m ago•0 comments

Show HN: Stripe default config often bypasses AVS

https://ghostaudit.io/
3•fitzz•23m ago•1 comments

Arcan 0.7.1 – Minutes to Midnight

https://arcan-fe.com/2025/12/27/arcan-0-7-1-minutes-to-midnight/
1•todsacerdoti•23m ago•0 comments

Show HN: Learn how to make your first open source pull request on GitHub

https://github.com/firstcontributions/first-contributions
3•sudo_bangbang•25m ago•0 comments

How to Get a Scholarship Without Ielts or Toefl (International Students)

https://grantjobsandscholarship.blogspot.com/2025/12/how-to-get-scholarship-without-ielts-or.html
1•frankchidera900•25m ago•0 comments

Ask HN: What's your health/fitness/wellness routine?

1•akhilnchauhan•29m ago•1 comments

Reasoning tools knowledgebase of thinking patterns from various domains

https://github.com/dvdarkin/reasoning-tools
1•dvdarkin•30m ago•1 comments

Show HN: Snapalabra – A daily exercise for learning new vocabulary

2•detectivestory•32m ago•0 comments

Dev-db: TypeScript-first mock database generator with realistic data in seconds

https://github.com/calvin-kimani/dev-db
1•kimanicalvin•33m ago•0 comments

Show HN: An AI pipeline to find anomalies in FDA medical device reports

https://maude-analysis.onrender.com/
2•smugesh•35m ago•0 comments

Show HN: AgentCmds – A directory of slash commands for AI agents

https://agentcmds.work/
2•ho_ba•43m ago•1 comments

Progressive disclosure is essential as AI capabilities grow, so does complexity

https://1984.design/psychology-of-design/progressive-disclosure/
1•kaizenb•43m ago•0 comments

GNU Taler v1.3 Released

https://www.taler.net/en/news/2025-13.html
5•midzer•45m ago•0 comments

My web framework is 1 py file, my CRM is 1 shell script, SQLite the 1 dependency

https://github.com/danielfalbo/prev.py/blob/main/prev.py
1•danielfalbo•46m ago•0 comments

Map of my personal data infrastructure (2021)

https://beepb00p.xyz/myinfra.html
1•Tomte•47m ago•0 comments

Before Electric Vehicles Became Political, There Was the Toyota Prius

https://www.nytimes.com/2025/12/27/business/electric-vehicles-poilitics-republicans-conservatives...
3•fleahunter•55m ago•0 comments

Maia Chess

https://www.maiachess.com/
1•plaguna•55m ago•0 comments

The US Must Stop Underestimating Drone Warfare

https://www.wired.com/story/the-us-must-stop-underestimating-drone-warfare/
1•fleahunter•56m ago•2 comments

Stop the slop by disabling AI features in Chrome

https://www.theregister.com/2025/12/26/disable_ai_features_chrome/
1•abdelhousni•58m ago•0 comments

AI's trillion-dollar opportunity: Context graphs

https://foundationcapital.com/context-graphs-ais-trillion-dollar-opportunity/
1•Arindam1729•59m ago•0 comments

Formulaic Delimiters in the Iliad and the Odyssey

https://glthr.com/formulaic-delimiters-in-the-iliad-and-the-odyssey
1•glth•1h ago•1 comments