frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•8mo ago

Comments

palata•8mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Verbalized Sampling: How to Mitigate Mode Collapse and Unlock LLM Diversity

https://arxiv.org/abs/2510.01171
1•ycombiredd•2m ago•0 comments

Trump 25% tariff on European allies until Denmark sells Greenland to US

https://www.theguardian.com/us-news/2026/jan/17/trump-tariff-european-countries-greenland
1•KnuthIsGod•3m ago•0 comments

SFTP Still Delivers the Goods

https://folio.co/blog/sftp-still-delivers-the-goods
1•whatrocks•4m ago•0 comments

Show HN: Figma-use – CLI to control Figma for AI agents

https://github.com/dannote/figma-use
1•dannote•6m ago•0 comments

Tunnl.gg: Expose Localhost to the Internet

https://github.com/klipitkas/tunnl.gg
1•thunderbong•10m ago•1 comments

What were books like in ancient Greece and Rome?

https://www.popsci.com/science/what-were-books-like-in-ancient-greece-and-rome/
1•WaitWaitWha•11m ago•0 comments

AIVO Standard Operational AI Reliance Observation Protocol

https://zenodo.org/records/18286718
1•businessmate•24m ago•1 comments

Is the World Random?

https://mantrna.com/astrobench
2•prabhatkr•34m ago•0 comments

Show HN: 30min video analysis for $0.003 via frame-tiling and Vision API

https://github.com/unhaya/vam-seek-ai
3•haasiy•37m ago•1 comments

300X fast clustering with rust-louvain for nodes

https://github.com/FastBuilderAI/rust-louvain
2•prabhatkr•37m ago•0 comments

Quantum Name Service (QNS)- Path to Web5

https://github.com/aevov/qns
2•cr8oscloud•39m ago•1 comments

Show HN: vr.dev – simple 3D/VR/XR portfolio and links (Meta hit hard this week)

https://www.vr.dev/
2•vrdev•40m ago•0 comments

Shackleton and the Endurance Expedition: Photos from the 1915 Disastrous Journey

https://www.utterlyinteresting.com/post/the-amazing-survival-story-of-ernest-shackleton-and-his-e...
4•nomagicbullet•41m ago•2 comments

Show HN: Task Orchestrator – Production Safety for Claude Code Agents

https://github.com/TC407-api/task-orchestrator
2•Travis_Cole•41m ago•1 comments

Model is intended for use particularly for language learning

https://huggingface.co/EnversonAI/DeepSeek-R1-FineTuned-AdaptiveQGen-COT
2•AslanMammadli•56m ago•1 comments

Ask HN: Is repalcing an enterprise product with LLMs a realistic strategy?

2•chandmk•56m ago•0 comments

Pushing the smallest possible change to production

https://ankursethi.com/blog/smallest-possible-change/
2•GeneralMaximus•57m ago•0 comments

Why Xcode's AI Writes Better SwiftUI Than Claude Code, Codex

https://www.ameyalambat.com/blog/swiftui-skills
4•ameyalambat128•59m ago•0 comments

Show HN: Open-Source DLP for LLMs

https://github.com/dorcha-inc/ceil-dlp
2•unclecolm•1h ago•0 comments

Cursor AI refusing $20 refund after 3 days of broken service

2•Waldopro•1h ago•1 comments

Show HN: Monitor Claude/Codex usage on Linux via browser cookies (no API keys)

https://github.com/NihilDigit/waybar-ai-usage
4•NihilDigit•1h ago•1 comments

Spectrum Brings NBA Games in Apple Immersive to Apple Vision Pro

https://www.apple.com/newsroom/2025/10/spectrum-brings-nba-games-in-apple-immersive-to-apple-visi...
1•Austin_Conlon•1h ago•0 comments

Crypto holder loses $283M to scammer impersonating wallet support

https://bsky.app/profile/web3isgoinggreat.com/post/3mcn26h32wp2q
7•unforgivenpasta•1h ago•1 comments

AI-Powered Diabetes Analysis with GitHub Copilot and Claude Skills [video]

https://www.youtube.com/watch?v=on5R6PWj8Wg
4•shanselman•1h ago•0 comments

No Chess on a Dead Planet

https://indianexpress.com/article/sports/chess/climate-activists-protests-hold-up-tata-steel-ches...
1•akbarnama•1h ago•0 comments

Show HN: Vanslist – Craigslist for tech freelancers, no fees

https://vanslist.com
1•netgeniuskid•1h ago•0 comments

Show HN: Turkish Sieve Engine – GPU-Accelerated Prime Number Generator

https://github.com/bilgisofttr/turkishsieve
1•bilgisoft•1h ago•0 comments

Tell HN: Google Trust and Safety is a joke

2•tokyobreakfast•1h ago•1 comments

The relentless rule of my fitness tracker

https://timharford.com/2025/10/the-relentless-rule-of-my-fitness-tracker/
10•Arnt•1h ago•2 comments

Aldrich Ames built a career on betraying trust

https://www.economist.com/obituary/2026/01/15/aldrich-ames-built-a-career-on-betraying-trust
1•petethomas•1h ago•0 comments