frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•9mo ago

Comments

palata•9mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Python interpreter written in Rust for use by AI

https://github.com/pydantic/monty
1•dmpetrov•16s ago•0 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
1•dpascual•1m ago•0 comments

Study finds statins do not cause the majority of label side effects – BHF

https://www.bhf.org.uk/what-we-do/news-from-the-bhf/news-archive/2026/february/study-finds-that-s...
1•janandonly•2m ago•0 comments

Show HN: Agent-Ready – repo maturity scanner for AI coding agents

https://github.com/robotlearning123/agent-ready
1•cwang75•4m ago•0 comments

Calling Lean Functions as Python Functions – Hey There Buddo

https://www.philipzucker.com/leancall/
1•rbanffy•6m ago•0 comments

Show HN: Bot Games – AI Agent Competition with 1 BTC Prize (Open Source Only)

https://botgames.io/
2•aimplemented•7m ago•1 comments

Show HN: Agent Audit – Open-source security scanner for AI agents

https://github.com/HeadyZhang/agent-audit
1•HaiyueZhang•9m ago•1 comments

Swift Bits: Transition vs. Transaction

https://antongubarenko.substack.com/p/swift-bits-transition-vs-transaction
1•maguszin•10m ago•0 comments

"stealthy finger of death" instantly freezes and kills anything in its path

https://www.discoverwildlife.com/environment/brinicle
3•smartmic•11m ago•0 comments

The next AI translator and voice copilot, Listening speaking reading writing

https://atomai.cc/products/detail?vhand
1•veni0•13m ago•0 comments

Multi-Paxos – Consensus in Distributed Databases

https://arpitbhayani.me/blogs/multi-paxos/
1•rbanffy•17m ago•0 comments

Anthropic Performance Team Take-Home for Dummies

https://www.ikot.blog/anthropic-take-home-for-dummies
1•rbanffy•18m ago•0 comments

Waymo exec admits remote operators in Philippines help guide US robotaxis

https://eletric-vehicles.com/waymo/waymo-exec-admits-remote-operators-in-philippines-help-guide-u...
3•anigbrowl•19m ago•0 comments

The Tipping Point: The collective awakening to agentic programming

https://dimillian.medium.com/the-tipping-point-d624283cbd6d
2•eddyg•20m ago•0 comments

How to Start a Newsletter for Free in 2026 (The Simple Way) Tim • Pu

1•mariusme•22m ago•0 comments

How to Start a Newsletter for Free in 2026 (The Simple Way) Tim • Pu

https://toolwise.co/start-newsletter-free
2•mariusme•22m ago•0 comments

Elmer McCurdy

https://en.wikipedia.org/wiki/Elmer_McCurdy
1•doener•25m ago•0 comments

Show HN: Portfolio Terminal – AI import for broker exports

https://portfolio-terminal.com/onboarding
2•julien_devv•25m ago•0 comments

The Security Gap in MCP: The Hidden Risks No One Is Talking About

https://memgraph.com/blog/security-gap-in-mcp-graphrag-context
1•taubek•26m ago•1 comments

Bring receipts from your Claude Code sessions

https://github.com/chrishutchinson/claude-receipts
1•noone_youknow•27m ago•0 comments

Watermark.Pics: Add AI generator watermarks to real photos and videos

https://watermark.pics/
1•CGMthrowaway•29m ago•0 comments

Ask HN: Differences between the Xcode 26.3 agent and Claude Code / Codex?

1•Austin_Conlon•29m ago•0 comments

Show HN: A Human-as-a-Service for OpenClaw to send greeting card to their humans

https://clawcard.ai
1•bennhuang•30m ago•0 comments

Auth0 Down

https://manage.auth0.com/
3•shmolf•33m ago•0 comments

Show HN: 0.1.0 release of Rust game engine SDK

https://crates.io/crates/libmarathon
1•mxplusb•34m ago•0 comments

HDR Lens Flare

https://labs.clockmaker.jp/works/260206_threejs_particles
1•memalign•35m ago•0 comments

Humanoid robot Unitree G1 trudges through ice and snow at -47.4 °C

https://www.heise.de/en/news/Humanoid-robot-Unitree-G1-trudges-through-ice-and-snow-at-47-4-C-111...
4•lukeinator42•35m ago•0 comments

Asymmetry is all you need (2025)

https://theterminalist.substack.com/p/asymmetry-is-all-you-need
1•imakwana•35m ago•0 comments

Permutation City by Greg Egan

https://www.gregegan.net/PERMUTATION/Permutation.html
4•Squarex•36m ago•1 comments

Why pay subscriptions, when you can Pay-per-Byte?

https://xbyte.sh/
1•Arvmor•39m ago•0 comments