frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Ask HN: Why would people in town be upset about a datacenter being installed?

1•jppope•9s ago•0 comments

WordPress at 23

https://wordpress.org/news/2026/05/wp23/
1•tolerance•47s ago•0 comments

3D Printed Building Completed 3 Months Faster Than Conventional Construction

https://cobod.com/europes-largest-3d-printed-apartment-building-completed-three-months-faster-tha...
1•geox•1m ago•0 comments

W3C Leadership Transition

https://www.w3.org/press-releases/2026/w3c-leadership-transition/
1•robin_reala•3m ago•0 comments

Why $/token is the wrong metric for Enterprise AI (agentic) applications

https://canyoncode.ai/blog/beyond-per-token
1•ravikiran9gopal•3m ago•0 comments

The Geometry of Superior Performance

https://nickmark.substack.com/p/the-geometry-of-superior-performance
1•bookofjoe•4m ago•0 comments

SMVE: Multi-Vector Retrieval That Just Works

https://www.topk.io/blog/20260311-smve-multi-vector-retrieval
1•gk1•4m ago•0 comments

Adam Keys Is Thinking

https://therealadam.com/2026/05/25/fits-on-a-floppy-great.html
1•surprisetalk•6m ago•0 comments

Containment Is Not Oversight

https://www.cognitivefusion.systems/insights/glasswing-003
1•JohnsonSLC•7m ago•0 comments

Playlist Folders are now available on Spotify mobile app

https://community.spotify.com/t5/Community-Blog/Playlist-Folders-are-Now-Available-on-Mobile-Here...
1•soheilpro•8m ago•0 comments

Spec Driven Development Isn't Waterfall

https://brooker.co.za/blog/2026/04/09/waterfall-vs-spec.html
2•ruptwelve•8m ago•0 comments

What types of exceptions should you catch?

https://www.pythonmorsels.com/what-types-of-exceptions-should-you-catch/
1•lukasgelbmann•10m ago•0 comments

The people who want AI to replace humanity

https://www.vox.com/future-perfect/489976/ai-successionism-transhumanism-posthumanism
2•mrdependable•10m ago•0 comments

Reading Observability Tools? That's a Robot's Job

https://www.lastweekinaws.com/blog/reading-observability-tools-thats-a-robots-job/
1•lukeasrodgers•11m ago•0 comments

Show HN: Firmion is a DSL for composing firmware images

https://github.com/steveking-gh/firmion
1•steve6390•11m ago•1 comments

Claudeverse – Mission Control for Parallel Claude Code Workers

https://claudeverse.ai
1•kcarriedo•11m ago•0 comments

CNN files lawsuit against Perplexity alleging unlawful content distribution

https://www.reuters.com/legal/litigation/cnn-files-suit-against-perplexity-alleging-unlawful-cont...
2•1vuio0pswjnm7•12m ago•0 comments

The Permanent Upper Crow

https://permanent-upper-crow.jasonwu.ink/
2•whiteblossom•13m ago•0 comments

DeepMind CEO Demis Hassabis says AGI may arrive by 2029, warns world unprepared

https://www.firstpost.com/tech/deepmind-ceo-demis-hassabis-says-agi-may-arrive-by-2029-warns-worl...
1•evo_9•13m ago•0 comments

You might not need jQuery

https://youmightnotneedjquery.com/
1•chistev•15m ago•0 comments

Meta launches Instagram, Facebook, and WhatsApp subscriptions

https://techcrunch.com/2026/05/27/meta-officially-launches-instagram-facebook-and-whatsapp-subscr...
4•hsuduebc2•15m ago•3 comments

Is this a supply-chain attack attempt?

https://github.com/CirclonGroup/angular-tree-component/issues/962
2•maratumba•16m ago•1 comments

Supreme Court lets Vermont's Meta suit proceed, open door to 50-state legal wave

https://fortune.com/2026/05/27/supreme-court-meta-instagram-teen-lawsuit-states-vermont/
1•1vuio0pswjnm7•16m ago•0 comments

Top grossing law firm Kirkland & Ellis set aside $500M to create own AI platform

https://www.ft.com/content/1825bb59-7b28-460d-b009-ee3cea5dbac3
2•cwwc•16m ago•1 comments

Microsoft's stance on zero day exploits is a dumpster fire of their own making

https://doublepulsar.com/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-m...
2•speckx•17m ago•0 comments

Gradle Is Javamaxxing

https://blog.gradle.org/gradle-is-javamaxxing
2•kassovic•17m ago•0 comments

Data pipelines powering generative AI systems rooted in invasions of privacy

https://www.amnesty.org/en/latest/news/2026/05/global-enormous-data-pipelines-powering-major-gene...
1•cdrnsf•17m ago•0 comments

Show HN: AI Skill to port PostgreSQL extensions to MySQL

https://github.com/villagesql/villagesql-skills
1•deesix•17m ago•0 comments

Wix cuts 20% of workforce in AI and currency restructuring

https://thenextweb.com/news/wix-is-cutting-20-of-its-workforce-as-a-strong-shekel-and-ai-competit...
1•thm•19m ago•0 comments

The Supernova That Sparked the Original Scientific Revolution

https://nautil.us/the-supernova-that-sparked-the-original-scientific-revolution-1281459
1•Brajeshwar•19m ago•0 comments