frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Show HN: Inbox Cleanup – get to inbox zero in Gmail

https://cleanup.upstream.do/
1•jtiret•1m ago•0 comments

AdGuard Home v1.0 Beta

https://adguard-dns.io/en/blog/adguard-home-v1-0-beta.html
1•ilreb•3m ago•0 comments

Show HN: An open-source LLM guardrail powered by Jev

https://github.com/gulbaki/jev-llm-guard
1•bakigul•3m ago•0 comments

Show HN: Dev tools that stay out of your way (JSON, Base64, JWT, etc.)

https://jsonformat.org/
1•stonewf•4m ago•0 comments

What Happened to Horses Is Happening to Us by CGP Grey (2014) [video]

https://www.youtube.com/watch?v=7Pq-S557XQU
1•axelfontaine•8m ago•0 comments

'Things may get ugly': Meta's new AI Muse is about to make the net more annoying

https://www.bbc.com/future/article/20260930-metas-new-ai-is-about-to-break-the-internet
2•ColinWright•8m ago•0 comments

Partial pooling as an answer to the reference class problem

https://sudippaul.substack.com/p/partial-pooling-as-an-answer-to-the
1•sebg•8m ago•0 comments

Mote – private chat rooms from a link, no accounts

https://motemsg.online/
1•robgunner•10m ago•0 comments

GPT-Synopsys: Frontier Intelligence to Revolutionize Chip Design

https://news.synopsys.com/2026-09-30-OpenAI-and-Synopsys-Announce-GPT-Synopsys-Frontier-Intellige...
1•giuliomagnifico•10m ago•0 comments

TanStack Start critical XSS in server functions (CVE-2026-102989)

https://tanstack.com/blog/tanstack-start-security-update-cve-2026-102989
1•joshcsimmons•10m ago•1 comments

Balloon Syndrome (Hedgehogs)

https://en.wikipedia.org/wiki/Balloon_syndrome
1•fidotron•12m ago•0 comments

Bugfix.es Launched

https://bugfix.es
2•Keloran•14m ago•0 comments

Paramount taking over Warner Bros for $110B

https://ir.corporate.discovery.com/news-and-events/financial-news/financial-news-details/2026/Par...
3•HelloUsername•14m ago•0 comments

Servers in Dawn-Dusk Orbit

https://www.johndcook.com/blog/2026/09/25/dawn-dusk-orbit/
1•sebg•20m ago•0 comments

TServe – Open-source inference server for time-series foundation models

https://github.com/sktime/tserve
1•armaghan_shakir•20m ago•0 comments

Calls to take down AI torture chamber on GitHub

https://github.com/login
2•rbbydotdev•23m ago•0 comments

We are all just LLMs

https://f055.net/opinion/we-are-all-just-llms/
3•f055•24m ago•2 comments

Meta Platforms (Meta) Stock Analysis 2026

https://marketinvestigation.beehiiv.com/p/meta-platforms-meta-stock-analysis-2026-is-meta-a-buy-h...
1•mapendembet•24m ago•0 comments

Report of Summit on PhD Math Education in the Age of AI [pdf]

https://cmsa.fas.harvard.edu/media/2026/09/Summit-on-PhD-Math-Education-in-the-Age-of-AI.pdf
2•sebg•25m ago•0 comments

ChatGPT Down

https://status.openai.com/incidents/01M3R1T4FCR1337FBBYY9K2RPB
1•pranshuchittora•28m ago•0 comments

European Union Kids Act Could End Stop Killing Games [video]

https://www.youtube.com/watch?v=mQRcK9nYg9g
2•lurtbancaster•29m ago•1 comments

Can companies like OpenAI keep getting away with what they are doing?

https://garymarcus.substack.com/p/can-companies-like-openai-keep-getting
3•AnodicElegy•29m ago•0 comments

Marc Rowan and Holly Goodrich are hiding their intimate relationship

https://nypost.com/2026/05/06/business/wall-street-giant-apollo-aims-to-open-second-headquarters-...
1•ndjfjj•33m ago•1 comments

Show HN: OrzChat, a minimalist anonymous random chat website

https://orzchat.com
1•davitmarg•33m ago•0 comments

Show HN: Modeling CHSH Degradation (S = 2.404) on Rigetti Cepheus-1-108Q

https://quantumcomputing.stackexchange.com/questions/46448/modeling-chsh-degradation-s-2-404-on-r...
1•kisnorbert•34m ago•0 comments

The Danger of Include: How C++'s Preprocessor Destroys Architecture

https://www.cppdepend.com/blog/the-danger-of-include-cpp-preprocessor/
1•cppfirst•35m ago•1 comments

Show HN: Walk the Endless Dungeon

https://the-endless.pages.dev/
2•olup•36m ago•0 comments

WindowStream

https://github.com/eugenyh/WindowStream
1•EugenyH•36m ago•0 comments

Why Agentic AI Governance Can't Be Bolted On

https://kimchi.dev/blog/why-agentic-ai-governance-cant-be-bolted-on
1•BlackPlot•37m ago•0 comments

Reliable social publishing agents with MCP

https://postsider.com/blog/reliable-social-publishing-agents-mcp/
1•luka5184•38m ago•0 comments