frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•8mo ago

Comments

palata•8mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Pebble Round 2

https://techcrunch.com/2026/01/02/pebble-reboots-its-thinnest-smartwatch-with-the-pebble-round-2/
2•noflag•1m ago•0 comments

Biggest Cybersecurity and Cyberattack Stories of 2025

https://www.bleepingcomputer.com/news/security/the-biggest-cybersecurity-and-cyberattack-stories-...
1•belter•4m ago•0 comments

Ask HN: What do you plan to read in 2026?

1•__patio•4m ago•0 comments

Giving Your Agent Eyes Is Not Enough

https://qckfx.com/blog/giving-your-agent-eyes-is-not-enough
1•chw9e•6m ago•0 comments

Science Is a Guessing Game

https://himanshusinghbisht.substack.com/p/science-is-a-guessing-game-conjectures
1•gilfoyle_7•8m ago•0 comments

I built a screen-aware desktop assistant; now it can write and use your computer

2•luthiraabeykoon•8m ago•1 comments

Ask HN: Why is iOS in-app purchase monetization so hard to learn as a system?

1•mnrj_vv•9m ago•0 comments

Does AI pose an existential threat to mathematicians?

https://kityates.substack.com/p/does-ai-pose-an-existential-threat
1•headalgorithm•11m ago•0 comments

Was It a Billion Dollar Mistake?

https://www.gingerbill.org/article/2026/01/02/was-it-really-a-billion-dollar-mistake/
1•gingerBill•12m ago•0 comments

Hacking Welfare Doubles Somalia's GDP

https://jessicar.substack.com/p/fraudulent-businesses-paid-the-equivalent
2•mensetmanusman•13m ago•1 comments

Show HN: I mapped System Design concepts to AI Prompts to stop bad code

https://github.com/nimin1/system-design-vibecoding
1•systemdesignai•14m ago•1 comments

Questions to ask yourself every year (2016)

https://stephango.com/40-questions
1•ayoisaiah•14m ago•0 comments

The Chicken Game and the Evolution of the DRAM Industry from 2006 to 2014 [pdf]

https://s-space.snu.ac.kr/bitstream/10371/95351/1/01%20Jeho%20Lee.pdf
2•walterbell•14m ago•0 comments

A "Fresh" New Terminal Text Editor

https://www.youtube.com/watch?v=dspEVA8eoUg
1•bane•15m ago•0 comments

Charlie Angus, Lafayette, Joni Askola, Outsiders Who See Collapse Coming First

https://www.americanmuckrakers.com/p/charlie-angus-lafayette-joni-askola
1•americanmuck•15m ago•0 comments

From many to one – parallel reductions on the GPU

https://double-dissent.fika.bar/from-many-to-one-01KDZ2KP81YSFJ4XJ1241QQK80
2•txus•16m ago•0 comments

How to add two vectors, fast

https://double-dissent.fika.bar/how-to-add-two-vectors-fast-01KDFNX4WQA7C70TZ19K8P1JAV
1•txus•16m ago•0 comments

A Study Is Retracted, Renewing Concerns About the Weedkiller Roundup

https://www.nytimes.com/2026/01/02/climate/glyphosate-roundup-retracted-study.html
2•instagib•19m ago•0 comments

Documented source code for The Sentinel on the BBC Micro

https://github.com/markmoxon/the-sentinel-source-code-bbc-micro
2•z303•19m ago•0 comments

The Click Communicator combines Blackberry function with modern smartphone form

https://www.androidpolice.com/clicks-launches-blackberry-like-communicator-phone/
2•cuu508•23m ago•0 comments

Show HN: Get company brand data API

https://www.brand.dev/
2•ICodeSometimes•26m ago•1 comments

The Handyman Principle: Why Your AI Forgets Everything

https://vexjoy.com/posts/the-handyman-principle-why-your-ai-forgets-everything/
3•AndyNemmity•31m ago•1 comments

Google AI Overviews put people at risk of harm with misleading health advice

https://www.theguardian.com/uk-news
4•chrisjj•34m ago•2 comments

Liars and Outliers: Enabling the Trust That Society Needs to Thrive, 2nd Edition

https://www.wiley.com/en-us/Liars+and+Outliers%3A+Enabling+the+Trust+that+Society+Needs+to+Thrive...
2•rendx•34m ago•1 comments

Why I'm skipping Dry January

https://www.statnews.com/2026/01/01/dry-january-moderate-drinking-research/
6•thm•36m ago•1 comments

How much the richest people made in 2025

https://qz.com/wealthiest-richest-trillions-billionaires-2025-musk-ellison
2•bgwalter•37m ago•0 comments

Tell HN: Check if the site is down. Also monitor your site

https://updown.fly.dev/
3•ejncman•38m ago•0 comments

Fighting Fire with Fire: Scalable Oral Exams

https://www.behind-the-enemy-lines.com/2025/12/fighting-fire-with-fire-scalable-oral.html
3•sethbannon•40m ago•0 comments

Nice to Meet You: Synthesizing Practical MLIR Abstract Transformers [pdf]

https://users.cs.utah.edu/~regehr/papers/popl26.pdf
2•PaulHoule•40m ago•0 comments

Accounting for Computer Scientists (2011)

https://martin.kleppmann.com/2011/03/07/accounting-for-computer-scientists.html
4•tosh•43m ago•0 comments