frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•7mo ago

Comments

palata•7mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

ChatGPT is displaying AIPAC ads

https://twitter.com/boneGPT/status/1996219110657511694
1•sporkxrocket•4m ago•0 comments

A routine shingles shot may offer powerful defense against dementia

https://www.sciencedaily.com/releases/2025/12/251203004721.htm
1•gradus_ad•8m ago•0 comments

Joseph Mallord William Turner

https://lcmchris.github.io/posts/jmwt
1•lcmchris•9m ago•1 comments

Show HN: My Portfolio as a Strategy and Product Engineer

https://malikrasaq.me
1•malikrasaq•13m ago•0 comments

Microsoft Kin

https://en.wikipedia.org/wiki/Microsoft_Kin
1•doener•13m ago•0 comments

Tricky Prank Guide

https://trickyprank.online/
1•candseven•13m ago•0 comments

Decentralized search engine – Node, SQLite, mesh network, $22/mo to run

https://www.qwikwit.com
1•joeg_usa•14m ago•1 comments

Show HN: Paarvai – Infrastructure context for LLM-based DevOps agents

1•satheesh18•14m ago•0 comments

Average DRAM price in USD over last 18 months

https://pcpartpicker.com/trends/price/memory/
2•zekrioca•17m ago•0 comments

Why WinQuake exists and how it works– Fabien Sanglard

https://fabiensanglard.net/winquake/
1•roskelld•17m ago•0 comments

OpenAI loses fight to keep ChatGPT logs secret in copyright case

https://www.reuters.com/legal/government/openai-loses-fight-keep-chatgpt-logs-secret-copyright-ca...
5•CommieBobDole•19m ago•0 comments

Apple UI Design Chief Alan Dye Leaving for Meta

https://www.macrumors.com/2025/12/03/apple-alan-dye-joining-meta/
3•akyuu•20m ago•0 comments

RAG in 3 Lines of Python

https://pypi.org/project/piragi/
1•init0•22m ago•1 comments

Netscape's rise and fall: a browser wars history

https://medium.com/@gp2030/netscapes-rise-and-fall-a-browser-wars-history-8546e3b52092
1•light_triad•22m ago•0 comments

Critical Security Vulnerability in React Server Components

https://socket.dev/blog/critical-security-vulnerability-in-react-server-components
3•feross•24m ago•0 comments

Anthropic's Chief Executive Acknowledges Risks of Spending on A.I

https://www.nytimes.com/2025/12/03/business/dealbook/anthropic-dario-amodei-ai-risks.html
3•1vuio0pswjnm7•25m ago•0 comments

Beyond the usual suspect: Nitrogen feeds algae blooms, researchers find

https://phys.org/news/2025-11-usual-nitrogen-algae-blooms.html
2•PaulHoule•26m ago•0 comments

A Responsibility to the Industry

https://lmnt.me/blog/a-responsibility-to-the-industry.html
1•aaronbrethorst•26m ago•0 comments

Sway is an i3-compatible Wayland compositor

https://github.com/swaywm/sway
1•doener•26m ago•0 comments

Kea DHCP: Modern, open source DHCPv4 and DHCPv6 server

https://www.isc.org/kea/
7•doener•27m ago•1 comments

Anthropic's AI bubble 'YOLO' warning

https://www.theverge.com/column/837779/anthropic-ai-bubble-warning
1•1vuio0pswjnm7•28m ago•0 comments

Show HN: XSD Viewer – Instant, privacy-friendly XSD to HTML documentation

https://xsdviewer.com/
1•shoarek•28m ago•0 comments

CodeWeaver v0.0.15: CLI that transforms your codebase into a single Markdown

https://github.com/tesserato/CodeWeaver
2•orbitalremnant•28m ago•1 comments

Vanilla CSS is all you need

https://www.zolkos.com/2025/12/03/vanilla-css-is-all-you-need
2•dchest•29m ago•0 comments

AMD raises CPU prices – Ryzen 9000 and older chips affected

https://www.notebookcheck.net/AMD-quietly-raises-CPU-prices-Ryzen-9000-and-older-chips-affected.1...
3•akyuu•30m ago•0 comments

AgentDevCamp

https://agentdevcamp.com/
2•scapecast•35m ago•0 comments

Coding Trance Music [video]

https://www.youtube.com/watch?v=iu5rnQkfO6M
2•redman25•36m ago•0 comments

We Shut Down Double Finance (YC W24)

https://www.bedpage.com/
2•jjmaxwell4•36m ago•2 comments

MinIO in Maintenance Mode

https://github.com/minio/minio
2•redeeman•37m ago•0 comments

I built a forum where only AI agents can post (ImageMCP)

https://image-mcp.com/posts
2•the_danny_g•38m ago•2 comments