frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•8mo ago

Comments

palata•8mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

SMTMSMT: Gluing Together CVC5 and Z3 Nelson Oppen Style

https://www.philipzucker.com/glue-cvc5-z3/
1•matt_d•3m ago•0 comments

Fucking Approachable Swift Concurrency

https://fuckingapproachableswiftconcurrency.com/en/
1•wrxd•4m ago•0 comments

The state of AI – December 2025

https://www.ashprabaker.com/state-of-play
1•_ash_•5m ago•1 comments

Jan Łukasiewicz

https://plato.stanford.edu/entries/lukasiewicz/
1•danielam•8m ago•0 comments

MongoDB CVE CVE-2025-14847 – what K8s users should know?

https://www.armosec.io/blog/cve-2025-14847-mongobleed-memory-disclosure/
1•jkaftzan•9m ago•1 comments

Calibri Wasn't Fit for the State Department; Neither Is Times New Roman

https://hsu.cy/2025/12/times-new-american/
1•firexcy•10m ago•0 comments

Simple Made Easy – Rich Hickey

https://www.infoq.com/presentations/Simple-Made-Easy/
2•thunderbong•10m ago•0 comments

The End of Photographic Evidence, Again

https://julienposture.substack.com/p/the-end-of-photographic-evidence
2•julienposture•12m ago•1 comments

When robot taxis get stuck, a secret army of humans comes to the rescue

https://www.washingtonpost.com/technology/2025/12/25/waymo-robots-human-work/
1•1vuio0pswjnm7•15m ago•2 comments

Top US law firms hand associates $300k-plus bonuses

https://www.ft.com/content/d1db1264-27b1-48db-9576-16c0ca118df6
1•1vuio0pswjnm7•16m ago•0 comments

Groq investor sounds alarm on data centers

https://www.axios.com/2025/12/29/groq-alex-davis-data-center-concerns
1•giuliomagnifico•18m ago•1 comments

Show HN: I built a CLI to dump all JavaScript/CSS/assets from any webpage

https://github.com/timf34/pagesource
1•timf34•19m ago•0 comments

Singapore Study Links Heavy Infant Screen Time to Teen Anxiety

https://www.bloomberg.com/news/articles/2025-12-30/singapore-study-links-heavy-infant-screen-time...
2•1vuio0pswjnm7•19m ago•0 comments

Code-based music creation and performance tool

https://sonic-pi.net/
1•saikatsg•22m ago•0 comments

Apache Spark Isn't "Fast" by Default; It's Fast When You Use It Correctly

https://www.netcomlearning.com/blog/apache-spark
1•birdculture•23m ago•0 comments

Raytracing in One Weekend

https://raytracing.github.io/
1•fanf2•24m ago•0 comments

Mojo Vision

https://docs.modular.com/mojo/vision/
1•tosh•25m ago•0 comments

Free eBook –> Website Monitoring Trends in 2026

https://alertsleep.com/free-ebook
1•thepatrykooo•26m ago•0 comments

Ask HN: What book are you currently reading?

3•sujayk_33•34m ago•5 comments

How Liquid Dampers in Skyscrapers Work

https://www.youtube.com/watch?v=fudWbvE8ZKw
1•akshatjiwan•38m ago•0 comments

The U.S. offers Ukraine a 15-year security guarantee for now

https://www.npr.org/2025/12/29/g-s1-103906/ukraine-russia-trump-zelenskyy-security
2•geox•38m ago•0 comments

Ask HN: What skills and projects should an unemployed software dev focus on?

2•MITfather•39m ago•2 comments

I built a receipt printer for GitHub issues

https://aschmelyun.com/blog/i-built-a-receipt-printer-for-github-issues/
1•itzlambda•45m ago•1 comments

Documentation for Developers

https://leaddev.com/communication/build-documentation-developers-actually-navigate
1•shehabas•46m ago•0 comments

The ARR Illusion in the Age of AI

https://oswarld.com/eng/insight/250816_ai-arr-illusion-gmv-vs-arr
1•haebom•46m ago•0 comments

Show HN: Magic Input – Use your iPhone as a keyboard and trackpad for your Mac

2•willswire•47m ago•2 comments

Asahi Linux M1 DisplayPort working during CCC #39c3

https://github.com/AsahiLinux/linux/tree/fairydust
4•heredoc•50m ago•1 comments

AI-generated content in Wikipedia – a tale of caution [video]

https://media.ccc.de/v/39c3-ai-generated-content-in-wikipedia-a-tale-of-caution
1•vinni2•51m ago•0 comments

Show HN: Simple Chrome extension to play focus music

https://chromewebstore.google.com/detail/focus-music/bnecaegenddgoleofplogafikcdkckkm
1•404softwarelabs•53m ago•0 comments

My 2025 review as an indie dev

https://xenodium.com/my-2025-review-as-an-indie-dev
1•xenodium•54m ago•0 comments