frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

UK PM gives tech firms ultimatum to block explicit images on children's phones

https://www.theguardian.com/technology/2026/jun/08/starmer-tech-firms-ultimatum-block-explicit-im...
1•tompagenet2•1m ago•0 comments

RayforceDB: Columnar Analytics and Graph Traversal in One Pipeline

https://rayforcedb.com/
1•tosh•4m ago•0 comments

Buy a train, bridge or tracks from the Swiss Railway

https://sbbresale.ch/
1•kisamoto•5m ago•0 comments

Let the agents democratize open source

https://world.hey.com/dhh/let-the-agents-democratize-open-source-9fd630a9
1•yulaow•5m ago•0 comments

TrailText – an ESP32 and LoRa off-grid messaging app

https://github.com/brunokeymolen/lora
1•brunokeymolen•5m ago•1 comments

Prompts I Reach for Every Week to Stay Unblocked as an Engineer

https://theaileverageweekly.com/posts/10-prompts-i-reach-for-every-week-to-stay-unblocked-as-an-e...
1•talvardi7•9m ago•0 comments

Show HN: CogCore – An API-native TypeScript runtime for building agents

https://github.com/carsonDB/CogCore
1•CarsonWu•10m ago•0 comments

Show HN: Email and identity stack for AI Agents

https://mailgent.dev/
2•DannyHeng•10m ago•0 comments

A Sustainable Git Option for Sovereign Solutions

https://code.kevwe.com/altgit.git/
1•kevwedotse•11m ago•0 comments

Substrate vs. Broker: Two Emerging Strategies for Enterprise AI

https://signal-memo.com/memo-salesforce-and-sap-are-making-opposite-bets-about-how-agents-will-us...
1•alex-ivan•12m ago•0 comments

GoSeofy

1•Juancabrera123•13m ago•0 comments

Doing Nothing at Work

https://www.seangoedecke.com/doing-nothing-at-work/
1•Sukram21•13m ago•0 comments

Gemini is currently charging us $1K per hour due a bug with the cache feature

https://twitter.com/_oliveiradanilo/status/2063660986213490882
1•jrflowers•15m ago•0 comments

Argentina's 'Madman': Inside the World of Javier Milei

https://www.aljazeera.com/features/longform/2026/6/6/argentinas-madman-inside-the-world-of-javier...
2•robtherobber•15m ago•0 comments

AI Has Come for Serif Fonts

https://www.wired.com/story/ai-has-come-for-serif-fonts/
2•unprovable•17m ago•1 comments

UK PM Starmer set to ban 'harmful' social media for under-16s

https://www.reuters.com/legal/litigation/uk-pm-starmer-set-ban-harmful-social-media-under-16s-202...
7•geox•34m ago•3 comments

The Cypherpunk Library

https://www.cypherpunkbooks.com
13•yu3zhou4•37m ago•0 comments

LLMs and Performative Productivity

https://joshcollinsworth.com/blog/productivity
1•gregnavis•39m ago•0 comments

Owning Your Dependencies

https://thestoicprogrammer.substack.com/p/owning-your-dependencies
2•birdculture•44m ago•1 comments

In Defense of YAML

https://opensource.posit.co/blog/2026-05-21_in-defense-of-yaml/
1•theanonymousone•48m ago•0 comments

Show HN: Free read-only script to find wasted AWS spend

https://cloudbudgetmaster.com/tools/aws-waste-finder/
1•samarth0211•48m ago•0 comments

The GitHub Copilot Bill Came Due. Here's What Engineering Leaders Should Do

https://blog.kilo.ai/p/the-github-copilot-bill-came-due
2•Aireen5858•53m ago•1 comments

Dao Heart 3.13 a symbolic safety layer for value drift and AI alignment research

https://github.com/Mankirat47/Dao-Heart-3.13
1•Mankirat47•56m ago•0 comments

OneDrive data now has an expiry date

https://ms365news.com/blogs/f/your-onedrive-data-now-has-an-expiry-data
5•taubek•59m ago•2 comments

String theory may be inevitable from basic assumptions about the universe

https://www.science.org/content/article/after-empty-promises-string-theory-finds-new-uses
2•isaacfrond•1h ago•0 comments

Cancelling Billionaires: A Review

https://www.counterpunch.org/2026/06/08/cancelling-billionaires-a-review/
2•daesorin•1h ago•0 comments

GitHub is (partially) down again. Do you look for alternatives?

1•Hypnosis6173•1h ago•1 comments

Bitcoin pump to $63,700 triggers the most short liquidations since late April

https://www.coindesk.com/markets/2026/06/08/bitcoin-pump-to-usd63-700-triggers-the-most-short-liq...
1•Varun-Sakhuja•1h ago•1 comments

Mimo v2.5 is better deal than DeepSeek v4 flash

1•shivang2607•1h ago•0 comments

Show HN: Image-3D: photo to 3D splat that runs in the browser

https://mukba.ng/image-3d/
1•mnorris•1h ago•0 comments