frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•7mo ago

Comments

palata•7mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Stratolaunch Systems

https://en.wikipedia.org/wiki/Stratolaunch_Systems
1•rolph•1m ago•0 comments

How I rehumanize the college classroom for the AI-augmented age

https://theconversation.com/how-i-rehumanize-the-college-classroom-for-the-ai-augmented-age-269168
1•eatonphil•3m ago•0 comments

How long does it take to get an EIN?

https://www.clerky.com/irs-ein-processing-times
1•swampthing•4m ago•0 comments

Can a slow-release bolus crack methane reduction for pasture raised cattle?

https://agfundernews.com/can-a-slow-release-bolus-crack-methane-reduction-for-pasture-raised-catt...
2•rmason•4m ago•0 comments

Runmat

https://runmat.org
1•limbicsystem•4m ago•0 comments

Are we stuck with the same Desktop UX forever? [video]

https://www.youtube.com/watch?v=1fZTOjd_bOQ
1•dsego•5m ago•0 comments

Footage appears to show aircraft larger than football field soaring over Calif

https://www.sfgate.com/bayarea/article/footage-aircraft-larger-football-field-california-21237276...
1•toomanyrichies•5m ago•0 comments

Living Particle System

https://creative-art-points.vercel.app/
1•lovegrenoble•5m ago•0 comments

DNS

1•code_Whisperer•6m ago•0 comments

Radiance Meshes for Volumetric Reconstruction

https://half-potato.gitlab.io/rm/
1•thethirdone•8m ago•0 comments

Newly launched document-to-portfolio-website, would love to get some feedback

https://boldlyhq.com/
1•yinychan•14m ago•1 comments

Referral to coach for fundraising for pre-revenue seed capital?

1•FWKevents•14m ago•0 comments

Fraudulent gambling network may be something more nefarious

https://arstechnica.com/security/2025/12/fraudulent-gambling-network-may-be-a-nation-state-spying...
2•PaulHoule•15m ago•0 comments

S&P500 retreats from record/closes down for week as investors rush from AI trade

https://www.cnbc.com/2025/12/11/stock-market-today-live-updates.html
2•MilnerRoute•16m ago•0 comments

Tanning beds triple melanoma risk, potentially causing broad DNA damage

https://news.northwestern.edu/stories/2025/12/tanning-beds-triple-melanoma-risk-potentially-causi...
3•geox•16m ago•0 comments

ARC-AGI-2 human baseline surpassed

https://www.lesswrong.com/posts/DX3EmhmwZjTYp9PBf/ai-performance-has-surpassed-a-human-baseline-o...
1•hugetim•17m ago•1 comments

Laid off from my dream job, what now?

https://debbie.codes/blog/laid-off-what-now/
2•cebert•18m ago•1 comments

Mark Bennett on Using Claude Code for Application Development

https://www.skmurphy.com/blog/2025/12/11/mark-bennett-on-using-claude-code-for-application-develo...
2•skmurphy•22m ago•1 comments

Why Everyone Is a DJ Now

https://kottke.org/25/12/this-is-why-everyone-is-a-dj-now
3•sieste•22m ago•0 comments

Amazon pulls AI recap from Fallout TV show after it made several mistakes

https://www.bbc.com/news/articles/c3r77j5nze5o
4•speckx•23m ago•0 comments

Socialism AI: A historic advance in the political education of the working class

https://ai.wsws.org/en
2•K7PJP•26m ago•1 comments

The choice between Rust and C-derived languages is not only about memory safety

https://bbuyukliev.blogspot.com/2025/12/the-choice-between-rust-and-c-derived.html
2•bluetomcat•27m ago•0 comments

Advice on Raising Seed Capital?

https://gotchafinder.ai
1•FWKevents•28m ago•1 comments

VMware kills vSphere Foundation in parts of EMEA

https://www.theregister.com/2025/12/11/vmware_kills_vsphere_foundation_parts_emea/
2•abdelhousni•31m ago•0 comments

Pre-PEP: Rust for CPython

https://discuss.python.org/t/pre-pep-rust-for-cpython/104906
2•BiteCode_dev•33m ago•0 comments

Remote Code Execution on a $1B Legal AI Tool

https://www.promptarmor.com/resources/casebreak-ai-phishing-and-rce-in-vlex
6•skcheetah•35m ago•0 comments

GNU Unifont

https://unifoundry.com/unifont/index.html
36•remywang•37m ago•10 comments

Noah Palansky Found PMF and the Road to a Successful Series A Raise [video]

https://www.youtube.com/watch?v=0UzJ4_EOl1g
1•rchachra•40m ago•0 comments

Tesla US sales drop to nearly 4-year low in November

https://www.reuters.com/business/autos-transportation/tesla-us-sales-drop-nearly-3-year-low-novem...
11•doener•40m ago•0 comments

Can something artificial create something real [video]

https://www.youtube.com/watch?v=a3hzuCLjQVo
1•rchachra•42m ago•0 comments