frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Group and Cluster Keywords for $4

https://keyworduniverse.co.uk/tools/ai-keyword-grouping
1•bullmers•1m ago•0 comments

Show HN: Electrolite – embeddable Electric-style sync for SQLite

https://github.com/russellromney/electrolite
1•russellthehippo•1m ago•0 comments

They Called It LISP For A Reason

https://gigamonkeys.com/book/they-called-it-lisp-for-a-reason-list-processing
1•optimalsolver•2m ago•0 comments

Connect Your App to Attention

https://docs.lovable.dev/integrations/attention
1•doener•2m ago•0 comments

Content automation system that ships 1B views per month

https://blog.bunnyhoneyclub.com/posts/content-automation-system-1-billion-views
1•shadowinbox•2m ago•0 comments

Richard Dawkins and the Claude Delusion

https://flux.community/matthew-sheffield/2026/05/richard-dawkins-and-the-claude-delusion/
1•coloneltcb•4m ago•0 comments

Peak lazy engineering: Let the code answer its own questions

https://dirac.run/posts/peak-lazy-engineering
1•GodelNumbering•5m ago•0 comments

Claude-meter: Monitor your Claude subscription usage in the macOS Menu

https://github.com/CrocSwap/claude-meter
1•dcolkitt•5m ago•1 comments

Show HN: ClankerView – AI agents browse your web app and give UX feedback

https://clankerview.com
1•hookey•7m ago•1 comments

AI Chatbots: Last Week Tonight with John Oliver (HBO) [video]

https://www.youtube.com/watch?v=Ykvf3MunGf8
1•atakan_gurkan•7m ago•0 comments

Rate Limiting with Nginx (2017)

https://blog.nginx.org/blog/rate-limiting-nginx
1•basilikum•7m ago•0 comments

Bash startup config file behavior (diagram)

https://github.com/rezrov/shellrc/blob/master/bash-startup.png
2•slowmover•8m ago•1 comments

Show HN: I Built a Retro Survival RPG in Vanilla JavaScript

https://stravaeger.com/
1•jasonkester•10m ago•2 comments

How to lose less money on prediction markets

https://pamacado.com/posts/prediction_markets/
1•mareoclasico•10m ago•0 comments

The RAG era is ending – a compilation-stage knowledge layer is what comes next

https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowled...
1•arizen•12m ago•0 comments

Make Technical Documentation Available for Local AI Use

https://www.heltweg.org/posts/make-technical-documentation-available-for-local-ai-use/
1•rhazn•14m ago•0 comments

ScyllaDB cut Sprig's read latency 4X after Redis and ClickHouse hit a wall

https://thenewstack.io/sprig-postgres-scylladb-migration/
1•Brajeshwar•14m ago•0 comments

Mine the Gap

https://telemetry.endeff.com/p/mine-the-gap
1•JMill•14m ago•0 comments

I Bought a TV with No 'Smart' Features [video]

https://www.youtube.com/watch?v=LJh72_O4pXE
2•throwaway270925•15m ago•0 comments

Corosio – coroutine-native C++20 networking library, successor to Boost.Asio

https://github.com/cppalliance/corosio
2•sgerbino•16m ago•0 comments

The CPanel Zero-Day Was Active for 64 Days Before Anyone Knew

https://webhosting.today/2026/05/03/the-cpanel-zero-day-was-active-for-64-days-before-anyone-knew/
2•aa_is_op•16m ago•0 comments

Hack your way to your girlfriend's heart

https://debbech.com/blog/post/hack_your_way_to_ur_gfs_heart/
1•bhhhhhhcc•20m ago•0 comments

VC fired all analysts, is using AI to help run deals for its new $75M fund

https://www.businessinsider.com/davidovs-venture-collective-dvc-ai-agents-talent-run-deals-2025-10
3•SenHeng•21m ago•2 comments

Show HN: Askdiff – Ask the Claude session that wrote your code in a diff viewer

https://github.com/narghev/askdiff
1•narghev•21m ago•0 comments

A Caddy Cert Expired Because Systemd-Resolved Was Selectively Broken

https://rant.mvh.dev/a-caddy-cert-expired-because-systemd-resolved-was-selectively-broken/
1•speckx•22m ago•0 comments

What's Blocking AI from Going Beyond Chatbots?

https://www.santoshkumarradha.com/writing/toward-theory-hax
1•youknowme123•24m ago•1 comments

Streaming Patterns with DuckDB

https://duckdb.org/2025/10/13/duckdb-streaming-patterns
1•tosh•24m ago•0 comments

The PHP License, Simplified

https://ben.ramsey.dev/blog/2026/05/the-php-license-simplified
1•Tomte•25m ago•0 comments

Show HN: AutoML Agents

https://github.com/haifengl/smile/tree/master/studio
3•haifeng•25m ago•0 comments

Show HN: I built a CLI to render lock file diffs human readable

https://github.com/Basliel25/lockdiff
1•Basgug25•26m ago•0 comments