frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Show HN: Oxlint plugin to auto-fix non-canonical Tailwind classes

https://github.com/maharshi365/oxlint-plugin-tailwind-canonical
1•maharship2022•2m ago•0 comments

Anthropic is lying: Moonshot is not routing to Claude

https://twitter.com/trydotworks/status/2098300730805284961
1•try-working•4m ago•0 comments

Proposal: Cmd/cgo: cgo without a C toolchain

https://github.com/golang/go/issues/81450
1•mappu•5m ago•0 comments

Predicting AI Job Exposure

https://www.ben-evans.com/benedictevans/2026/5/24/ai-job-exposure
1•saikatsg•6m ago•0 comments

Read Independent Fiction

https://eveningnotes.bearblog.dev/read-independent-serialized-fiction-and-short-fiction-web-novel...
1•saikatsg•8m ago•0 comments

The Omarchy Doctrine

https://omarchy.org/doctrine/
1•Tomte•10m ago•0 comments

For most of history, people's conversations, thoughts, and finances were private

https://grapheneos.social/@GrapheneOS/117249893761790371
1•Cider9986•12m ago•0 comments

Cursor Projects

https://cursor.com/blog/projects
3•deadalus•12m ago•0 comments

Show HN: Automatically keep track of all features implemented in a project

https://github.com/netizer/feature-ledger
1•krzysiek•13m ago•0 comments

Roads – the UKs favourite roads website

https://www.roads.org.uk/
2•ColinEberhardt•19m ago•0 comments

Only 31% of startup accelerators publish what cheque they write

https://accelerator.directory/methodology
2•buidlr•20m ago•0 comments

Astra for Coding: Why Are We Doing This Again?

https://lucumr.pocoo.org/2026/9/7/astra-why/
31•manojbajaj95•23m ago•7 comments

Vinetaro Drops

https://www.facebook.com/VinetaroDropsTry/
1•taxygamu•24m ago•0 comments

Anthropic blocks 'malicious use' of AI that could develop biological weapons

https://www.bbc.com/news/articles/cx2zrrpkx20o
2•mgh2•27m ago•0 comments

Course Review: TrainSec Malware Analyst Professional – Level 1

https://medium.com/@1200km/course-review-trainsec-malware-analyst-professional-level-1-203ca89b76a2
1•1200km•31m ago•0 comments

Large Language Models Reflect the Ideology of Their Creators

https://arxiv.org/abs/2410.18417
2•zvr•32m ago•0 comments

Gonc – Netcat with P2P Nat Traversal

https://github.com/threatexpert/gonc
3•gonc_cc•34m ago•0 comments

In Praise of Non-Alphanumeric Identifiers (2008)

https://prog21.dadgum.com/20.html
1•anoushiravan•35m ago•0 comments

Gaza documentary Naza receives record 25-minutes ovation at Venice Film Festival

https://www.thenationalnews.com/arts-culture/film-tv/2026/09/11/gaza-documentary-naza-receives-re...
3•teleforce•35m ago•0 comments

Microsoft Brings "Age Verification" System to Windows

https://reclaimthenet.org/microsofts-brings-verification-system-to-windows
4•PPBear•36m ago•0 comments

Cross-App TCP Hijacking and DNS Cache Poisoning via Malicious Local App

https://arxiv.org/abs/2609.09345
2•sbulaev•39m ago•0 comments

Show HN: SideNote Pro – Native Windows 11 AI beside your work

https://sidenotepro.com
1•fortisnode•39m ago•0 comments

9/11 footage is reaching new audiences – and fueling old conspiracy theories

https://www.cnn.com/2026/09/10/media/911-footage-social-media-conspiracy-theories
2•1659447091•41m ago•0 comments

The 9/11 Cars That Never Made It Home [video]

https://www.youtube.com/watch?v=COVCuPtNDO4
1•fortran77•42m ago•0 comments

STS-51-F Abort-to-Orbit (1985)

https://en.wikipedia.org/wiki/STS-51-F
2•schoen•43m ago•1 comments

ARM's 2026 'Tech' Day Is a Self-Inflicted Wound

https://www.semiaccurate.com/2026/09/07/arms-2026-tech-day-is-a-self-inflicted-wound/
2•fork-bomber•44m ago•0 comments

Show HN: I pointed 11 cold AI agents at my own product. 3 finished

https://pact0.com/notes/agents-vs-our-own-product
3•benban•46m ago•0 comments

The Mailman Kept Crossing Out My Address

https://idiallo.com/blog/sharing-a-name
1•firefoxd•48m ago•0 comments

The Scientific Challenge Atlas

https://micde.umich.edu/scientific-challenge-atlas/
2•JohnHammersley•50m ago•0 comments

Personal statement on joining the OpenAI board

https://paulfchristiano.substack.com/p/personal-statement-on-joining-the
2•doener•51m ago•0 comments