frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•7mo ago

Comments

palata•7mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

How to Detect Deepfakes

https://telmo.dev/posts/deepfake_detection/
1•telmop•47s ago•0 comments

Copywriters reveal how AI has decimated their industry

https://www.bloodinthemachine.com/p/i-was-forced-to-use-ai-until-the
1•thunderbong•2m ago•0 comments

Show HN: Founder Market Fit Mapping Tool a.k.a. "Coco"

https://thisiscoco.app/
1•theDGA•4m ago•0 comments

Show HN: Open-source AI agent for spreadsheets

https://github.com/raj-khare/offset
1•raj_khare•6m ago•0 comments

GraphQL: The Enterprise Honeymoon Is Over

https://johnjames.blog/posts/graphql-the-enterprise-honeymoon-is-over
2•johnjames4214•7m ago•0 comments

JustHTML is an example of vibe engineering in action

https://simonwillison.net/2025/Dec/14/justhtml/
2•lumpa•7m ago•0 comments

Light-based catalyst-free conversion of CH4 and CO2

https://www.nature.com/articles/s41566-025-01800-3
1•westurner•7m ago•2 comments

AI Is Breaking the Internet as We Know It [video]

https://www.youtube.com/watch?v=lPBwJz45nrk
1•indigodaddy•8m ago•0 comments

Show HN: a Pager

https://www.udp7777.com/
1•keepamovin•10m ago•1 comments

Gimp Art

https://harambe.merkoba.com/post/01kcex8j4v
1•the_stocker•13m ago•0 comments

Show HN: Depup – a dependency upgrade advisor for Python projects

https://github.com/saran-damm/depup
2•saran-damm•14m ago•0 comments

So, about this AI thing

https://paulkrugman.substack.com/p/talking-with-paul-kedrosky
2•mooreds•15m ago•0 comments

You're Thinking About AI and Water All Wrong

https://www.wired.com/story/karen-hao-empire-of-ai-water-use-statistics/
1•foobarqux•15m ago•0 comments

Show HN: Axiom for Claude Code – Coding skills for iOS devs

https://charleswiltgen.github.io/Axiom/
1•CharlesW•16m ago•0 comments

How to Choose the Best Programming Languages, Libraries, and Patterns

https://www.freecodecamp.org/news/how-to-choose-the-best-programming-languages-libraries-and-patt...
1•dxs•16m ago•0 comments

Teaching Quality

https://hollisrobbinsanecdotal.substack.com/p/teaching-quality
1•paulpauper•17m ago•0 comments

Hyper-Util Composable Pools

https://seanmonstar.com/blog/hyper-util-composable-pools/
2•todsacerdoti•19m ago•0 comments

The case for taking the giving what we can pledge

https://benthams.substack.com/p/a-life-that-cannot-be-a-failure
1•paulpauper•20m ago•0 comments

A Governance Innovation Crisis

https://www.overcomingbias.com/p/a-governance-innovation-crisis
1•paulpauper•22m ago•0 comments

The Scramble for the Seafloor

https://www.nybooks.com/online/2025/12/10/the-scramble-for-the-seafloor/
1•mitchbob•25m ago•1 comments

Hashcards: A Plain-Text Spaced Repetition System

https://borretti.me/article/hashcards-plain-text-spaced-repetition
2•thomascountz•25m ago•0 comments

Ask HN: What Are You Working On? (December 2025)

3•david927•25m ago•5 comments

Elon Musk Is Wrong About Basic Income and Crime: Here Is the Evidence He Ignored

https://scottsantens.substack.com/p/elon-musk-is-wrong-about-universal-basic-income-ubi-and-crime
3•2noame•26m ago•2 comments

Nippon Steel's Acquisition of US Steel: A $15B Deal

https://imaa-institute.org/blog/nippon-steels-acquisition-of-us-steel/
1•eatonphil•27m ago•0 comments

Job apocalypse? Humbug AI is creating new occupations

https://www.economist.com/business/2025/12/14/job-apocalypse-humbug-ai-is-creating-brand-new-occu...
2•edward•27m ago•0 comments

The Twelve Slices of Christmas: How Vasco Chained the Chaos

https://perladvent.org/2025/2025-12-14.html
1•oalders•30m ago•1 comments

Inside The Dark and Predatory World of Crypto Casinos

https://www.nytimes.com/interactive/2025/12/09/us/crypto-casinos-gambling-streamers.html
1•thm•31m ago•0 comments

The next version of the web will be built for machines, not humans

https://www.economist.com/interactive/science-and-technology/2025/12/10/the-next-version-of-the-w...
1•edward•31m ago•0 comments

The best software podcast episodes I ever heard

https://thundergolfer.com/ten-best-software-podcast-episodes
2•jonobelotti•32m ago•0 comments

I added native time awareness to CrewAI to fix LLM date hallucinations

https://github.com/crewAIInc/crewAI/pull/4082
1•sherwin27•32m ago•1 comments