frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•12mo ago

Comments

palata•12mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Iran defies Trump's blockade as oil prices soar

https://www.france24.com/en/live-news/20260430-iran-defies-trump-s-blockade-as-oil-prices-soar
1•geox•42s ago•0 comments

SCOTUS: Voters Can Be Disenfranchised Now

https://www.theatlantic.com/ideas/2026/04/vra-supreme-court-callais-decision/686997/
1•Arodex•54s ago•0 comments

GitHub Copilot silently inserts itself as a co-author

https://github.com/orgs/community/discussions/194075
1•tjek•1m ago•0 comments

Some schools consider eliminating homework

https://www.npr.org/2026/04/28/nx-s1-5795647/should-schools-get-rid-of-homework
1•isaacfrond•2m ago•0 comments

Show HN: Multiplayer Voronoi

https://voronoi.charlespierre.fr/
1•cpa•2m ago•0 comments

Show HN: Brifly – stop re-explaining your codebase to Claude Code every week

https://www.getbrifly.com/
1•dbarabashdev•3m ago•0 comments

C++26: String and String_view Improvements

https://www.sandordargo.com/blog/2026/04/29/cpp26-string-string_view-improvements
1•jandeboevrie•3m ago•0 comments

Fake PoC, Real Backdoor: How a Typosquatted Repo Weaponized CVE-2026-31431

https://ip-ninja.com/blog/typosquatted-cve-2026-31431-fake-exploit
1•d4n3ws•4m ago•0 comments

Show HN: Token Thermodynamics

https://mybinder.org/v2/gist/gpavanb1/30a27c0592dbb23311f165dae4549309/HEAD?urlpath=voila%2Frende...
1•gpavanb•7m ago•0 comments

Chrome looks set to ship an LLM Prompt API to the web. We oppose this API

https://mastodon.social/@firefoxwebdevs/116492853483021978
1•Vinnl•8m ago•0 comments

AI doesn't kill SaaS. It kills bad priorities

https://erdincakkaya.substack.com/p/ai-doesnt-kill-saas-it-kills-bad
1•erdinc•11m ago•0 comments

Inventions for battery reuse and recycling increase more than 7-fold in last 10y

https://www.epo.org/en/news-events/news/inventions-battery-reuse-and-recycling-increase-more-seve...
2•JeanKage•11m ago•0 comments

Amber-Lang 0.6.0 – New release (Bash transpiler)

https://docs.amber-lang.com/getting_started/whats_new
1•mte90•14m ago•0 comments

The Perfect Code Review: How to Reduce Cognitive Load While Improving Quality

https://bastrich.tech/perfect-code-review/
1•birdculture•15m ago•0 comments

Telnyx now offers WhatsApp Business Calling

https://telnyx.com/products/whatsapp-calling
1•deniztelnyx•17m ago•0 comments

Link Wallet for Agents

https://link.com/en-no/agents
1•punnerud•19m ago•0 comments

Made free polished workspaces for Chrome that sync via Google (zero telemetry)

https://www.superchargebrowser.com/navigation/
1•superchargeext•20m ago•0 comments

TierPad

https://tierpad.com
1•tinytoyou•21m ago•0 comments

Show HN: Arkloop – Open-source, local-first Agent client

https://github.com/qqqqqf-q/arkloop
1•qqqqqf•22m ago•0 comments

NPM supply-chain attack is targeting the SAP developer ecosystem

https://www.aikido.dev/blog/mini-shai-hulud-has-appeared
1•raffael_de•23m ago•1 comments

Elon Musk said OpenAI betrayed him after Microsoft deal

https://www.sfchronicle.com/tech/article/elon-musk-openai-trial-22231495.php
2•isaacfrond•27m ago•1 comments

Chasing a SharedKey signature mismatch: fix azurerm_storage_table_entity

https://topaz.thecloudtheory.com/blog/debugging-table-entity-auth/
1•kamilmrzyglod•28m ago•0 comments

Microsoft Edit 2.0.0 – A compiler for syntax highlighting

https://github.com/microsoft/edit/releases/tag/v2.0.0
1•tjek•29m ago•0 comments

How to Make a Progressive Web App Out of Your Existing Website (2019)

https://xeiaso.net/blog/progressive-webapp-conversion-2019-01-26/
1•xeonmc•31m ago•0 comments

Private LLM vs. ChatGPT

https://morai.eu/private-llm-vs-chatgpt-in-business-when-it-makes-sense-and-when-it-doesnt/
1•readow•34m ago•0 comments

Found 10 Genius Clocks Every Science Lover Needs [video]

https://www.youtube.com/watch?v=-ved6HMJpcw
1•mdp2021•37m ago•0 comments

How AI Is Transforming Education

https://longtermemory.com/b/ai-transforming-education/
2•aledevv•39m ago•0 comments

Specialization in Stable Rust

https://goldstein.lol/posts/stable-specialization/
2•fanf2•42m ago•0 comments

Multi Censured Nobel Prizes – Universal Physics

https://gitlab.com/users/btpfromsosua/starred
1•machardmachard•42m ago•0 comments

Australia Kangaroo Coin, the World's Largest Gold Coin

https://www.perthmint.com/visit/attractions/one-tonne-gold-coin/
1•nephihaha•42m ago•2 comments