frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Voltage Tester vs. Multimeter

https://www.techtownforum.com/knowledge-base/article/equipment-appliances/tech-tools/voltage-test...
1•susam•1m ago•0 comments

Digital Hopes, Real Power: From Connection to Collective Action

https://www.eff.org/deeplinks/2026/04/digital-hopes-real-power-connection-collective-action
1•hn_acker•1m ago•0 comments

Auto CVE Checker–open-source CVE+SBoM+C/C++ scanner for ISO/SAE 21434 compliance

https://github.com/devender-sharma-emb/automotive-cve-tool
1•devvender•1m ago•0 comments

I tracked 7,700 UK petrol stations every 10 minutes for 3 months

https://www.fuelinsight.co.uk
1•theazureguy•2m ago•1 comments

A Tale of Two Job Markets

https://www.youtube.com/watch?v=ugzw5I3Vako
1•gandalfgeek•4m ago•0 comments

Astro Removed Its Llms.txt

https://dacharycarey.com/2026/05/04/astro-removed-llms-txt/
1•taubek•4m ago•0 comments

Karabiner-Elements 16.0.0

https://karabiner-elements.pqrs.org/docs/releasenotes/
1•pretext•5m ago•0 comments

Removable batteries in smartphones will be mandatory in the EU starting in 2027

https://www.ecopv-eu.com/en/blog-en/replaceable-smartphone-batteries-2027-eu-regulation/
2•rdeboo•7m ago•0 comments

ConsentFix v3 attacks target Azure with automated OAuth abuse

https://www.bleepingcomputer.com/news/security/consentfix-v3-attacks-target-azure-with-automated-...
1•Brajeshwar•9m ago•0 comments

Show HN: SharkAuth – Auth server for AI agent delegation

https://github.com/shark-auth/shark
1•raulgooo•9m ago•0 comments

Building a new enterprise AI services company with Blackstone, H&F, and Goldman

https://www.anthropic.com/news/enterprise-ai-services-company
1•yla92•12m ago•0 comments

You Were Tricked: An 8000 Word Response to Lars Lofgren's Viral Codesmith Piece

https://michaelnovati.substack.com/p/a-response-to-lars-lofgrens-codesmith
1•michaelnovati•14m ago•1 comments

29th August 2026: A Scenario

https://martinalderson.com/posts/august-29-2026-a-scenario/
1•martinald•15m ago•0 comments

Automatically switch Android's dark mode using ambient light sensor

https://www.howtogeek.com/i-ditched-sunrisesunset-dark-mode-for-this-android-app-it-uses-your-lig...
1•politelemon•15m ago•0 comments

Show HN: KIP Pattern – A React architecture pattern for true encapsulation

https://github.com/Miladxsar23/kip-pattern
1•milad_shirian•16m ago•0 comments

Send Large Files Online – Free, Secure and Unlimited

https://fromsmash.com/
1•janandonly•18m ago•0 comments

How HN: BibCrit – LLM analysis grounded in real manuscript corpus data

https://bibcrit.app/
1•jossifresben•21m ago•1 comments

More than half of pilots have fallen asleep while in charge of a plane (2013)

https://www.bbc.com/news/uk-24296544
2•johnbarron•24m ago•1 comments

Flipper: Beautiful, performant feature flags for Ruby

https://github.com/flippercloud/flipper
1•thunderbong•25m ago•0 comments

Analyzing the Patterns of Numbers in 10M Passwords (2015)

https://minimaxir.com/2015/02/password-numbers/
1•downbad_•28m ago•1 comments

Show HN: Looq, the capabilities macOS Quick Look should have shipped with

https://parcse.com/looq
3•parcse•28m ago•0 comments

Show HN: Capsule Bash – Sandboxed Bash for Agents

https://github.com/capsulerun/bash
1•mavdol04•28m ago•2 comments

Pomiferous: The most extensive apples (pommes) database

https://pomiferous.com/
1•Ariarule•30m ago•0 comments

How citations ruined science

https://davidoks.blog/p/how-citations-ruined-science
1•jprs•32m ago•0 comments

Are closed social networks inevitable? (2010)

https://danluu.com/open-social-networks/
2•downbad_•33m ago•1 comments

Knowledge Infra for Agents and Humans

https://dosu.dev
1•devstein•33m ago•0 comments

LandingRank – community-ranked landing page directory with daily Elo battles

https://landingrank.com
1•_FakeBanana_•33m ago•0 comments

Systems Are Visual – This Is a Better Way to Write Them

https://toolkit.whysonil.dev/lab-notebook/
3•otterwilde2•36m ago•0 comments

Vitexec – allow agents to test Vite apps through injected code

https://www.youtube.com/watch?v=yhIOSjp6pqs
1•BelaBohlender•36m ago•0 comments

They Left Receipts: Inside Charming Kitten's Crypto Procurement Network

https://caudena.com/charming-kitten-crypto-procurement-network/
2•caudena•38m ago•0 comments