frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•11mo ago

Comments

palata•11mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Statistics of the World: 440 indicators for 218 countries, free API

https://statisticsoftheworld.com
1•sotwdata•43s ago•0 comments

Wine 11.6 – Run Windows Applications on Linux, BSD, Solaris and macOS

https://www.winehq.org/announce/11.6
1•neustradamus•50s ago•0 comments

Show HN: Cursor extension to track LLM cache TTL

https://github.com/agastalver/cache-timer-extension
1•agastalver•5m ago•0 comments

Trump seeks $1.5T for just defence, alongside domestic spending cuts

https://www.bbc.com/news/articles/crr1q4kjvn2o
3•throw0101c•5m ago•0 comments

Gcannon – fastest HTTP load generator for Linux

https://github.com/MDA2AV/gcannon
1•MDA2AV•6m ago•0 comments

US economy beats expectations to add 178,000 jobs in March

https://www.ft.com/content/82c1795b-704a-4da3-82ec-2f9cd52de01e
2•alephnerd•7m ago•0 comments

AI's Next Frontier: Insights from Jeff Dean and Bill Dally In

https://www.youtube.com/watch?v=g8BuAtM3fp4
1•guiambros•7m ago•0 comments

Elon Musk Requires Banks Behind SpaceX IPO to Buy Grok Subscriptions

https://www.forbes.com/sites/tylerroush/2026/04/03/elon-musk-requires-banks-behind-spacex-ipo-to-...
1•CyberMacGyver•9m ago•0 comments

Improving storage efficiency in Magic Pocket, Dropbox's immutable blob store

https://dropbox.tech/infrastructure/improving-storage-efficiency-in-magic-pocket-our-immutable-bl...
5•laluser•9m ago•0 comments

Blog Refresh

https://kataqatsi.com/ideas/13
1•kataqatsi•10m ago•1 comments

Show HN: LunaLora: Multi-LoRA System to Combat Catastrophic Forgetting

https://github.com/SphericalCowww/ML_LunaLoRA
1•SphericalCowww•10m ago•1 comments

Fatal addiction: Authors accuse Apple of destroying Japan's tech industry

https://theworld.org/stories/2016/07/30/fatal-addiction-authors-accuse-apple-destroying-japans-te...
1•zahirbmirza•15m ago•1 comments

It's the Internet, Stupid (2025)

https://www.persuasion.community/p/its-the-internet-stupid
2•mitchbob•17m ago•1 comments

Nikon Z9 Aboard the Artemis II Moon Mission at the Last Minute

https://petapixel.com/2026/04/02/a-nikon-z9-made-it-aboard-the-artemis-ii-moon-mission-at-the-las...
1•DASD•18m ago•0 comments

The problems with Big Tech AI data collection

https://nextcloud.com/blog/the-problems-with-big-tech-ai-data-collection-privacy-concerns-and-how...
3•devonnull•19m ago•0 comments

The danger of military AI isn't killer robots; it's worse human judgement

https://www.defenseone.com/technology/2026/03/military-ai-troops-judgement/412390/
4•speckx•21m ago•2 comments

HN: MCP-authz – runtime authorization middleware for MCP tool calls

https://github.com/soumyasagiri/mcp-authz
2•soumyasagiri•22m ago•0 comments

Attackers Are Hunting High-Impact Node.js Maintainers with Social Engineering

https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers
2•pier25•24m ago•2 comments

Researchers Secure NSF Grant to Test Ancient Fern as Carbon Offset Soln (2025)

https://news.stonybrook.edu/university/sbu-researchers-secure-nsf-grant-to-test-ancient-fern-as-c...
1•littlexsparkee•24m ago•0 comments

Rainy-City.com

https://rainy-city.com
1•mnky9800n•26m ago•0 comments

Show HN: Grammarly for tweet reach – 36 rules from X's source

https://github.com/AytuncYildizli/reach-optimizer
4•aytuncyildizli•28m ago•1 comments

Show HN: We're building an AI hedge fund

https://rallies.ai/arena
5•rallies•28m ago•11 comments

A Visual Tour of Modern LLM Architectures

https://www.youtube.com/watch?v=CepbWmGie0E
2•mdp2021•29m ago•0 comments

Pushing Claude Code Further with Spec Driven Development

http://gordonburgett.net/posts/2026/03_spec-driven-development/
3•gburgett•30m ago•0 comments

Craigslist Made Me Rich. Giving the Money Away Is Easy.

https://www.nytimes.com/2026/03/30/opinion/giving-pledge-philanthropy.html
3•bookofjoe•30m ago•1 comments

The Cost of Fewer Tokens: Context Efficiency Makes Playwright CLI Slower

https://outpost.ranger.net/post/the-hidden-cost-of-fewer-tokens/
1•mroset•32m ago•0 comments

Show HN: Lustre – MCP server giving AI tools premium Flutter components

https://www.npmjs.com/package/lustre-mcp
1•deltaops•34m ago•0 comments

ChatGPT vs. Electrical Engineering Graduate-Level Course Final Exam

https://www.youtube.com/watch?v=QTm8G2rQYTY
1•guiambros•34m ago•0 comments

Toasty, an Async ORM for Rust

https://tokio.rs/blog/2026-04-03-toasty-released
1•carllerche•35m ago•0 comments

The false dawn of the post-literate society

https://unherd.com/2026/04/the-false-dawn-of-the-post-literate-society/
2•anarbadalov•36m ago•0 comments