frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•10mo ago

Comments

palata•10mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

1•finiking•27s ago

Apple Developer Security Event

https://www.youtube.com/watch?v=UZeSyodAszc
1•de_aztec•1m ago•0 comments

Show HN: Blinkit MCP – Let Claude order groceries

https://github.com/hereisSwapnil/blinkit-mcp
1•hereisSwapnil•2m ago•0 comments

Sam Altman asks if government can nationalize artificial general intelligence

https://thenewstack.io/openai-defense-department-debate/
2•MilnerRoute•3m ago•0 comments

Kopia – Encrypted, Compressed, and Deduplicated Backups

https://kopia.io/
1•GTP•3m ago•0 comments

Show HN: Reformat Word document citations (APA/Vancouver) in <1 second

https://github.com/brodie-neuro/ScholarRef
1•brodie-neuro•4m ago•1 comments

Website is a big waste of time

https://spacepanda.se/articles/toxic_pages.html
1•speckx•4m ago•0 comments

GPT 5.4 Thinking and Pro

https://twitter.com/OpenAI/status/2029620619743219811
4•twtw99•4m ago•0 comments

AI Slop Bores Me

https://www.youraislopbores.me/
1•KuSpa•4m ago•0 comments

Bron-Crypto: A Go cryptography library focusing on MPC

https://github.com/bronlabs/bron-crypto
1•somezero•4m ago•0 comments

Data Science Weekly – Issue 641

https://datascienceweekly.substack.com/p/data-science-weekly-issue-641
1•sebg•5m ago•0 comments

Pentagon Says It's Told Anthropic the Firm Is Supply-Chain Risk

https://www.bloomberg.com/news/articles/2026-03-05/pentagon-says-it-s-told-anthropic-the-firm-is-...
1•nickysielicki•7m ago•0 comments

What Is Phenomenology? [video]

https://www.youtube.com/watch?v=TG3fq-KHDDw
1•modinfo•7m ago•0 comments

A 2024 Plea for Lean Software (with running code)

https://berthub.eu/articles/posts/a-2024-plea-for-lean-software/
1•tosh•8m ago•0 comments

GPT-5.4 Thinking and GPT-5.4 Pro

https://twitter.com/i/status/2029620619743219811
8•denysvitali•9m ago•1 comments

Ask HN: Claude Regression for Anyone Else?

2•rudedogg•10m ago•0 comments

Ask HN: Moving from Software Engineer to PM or another area?

1•mr_00ff00•10m ago•1 comments

Oracle Plans Job Cuts in Face of AI Cash Crunch

https://www.bloomberg.com/news/articles/2026-03-05/oracle-layoffs-to-impact-thousands-in-ai-cash-...
1•speckx•11m ago•0 comments

Show HN: A unified event protocol dashboard for startup founders

https://founders-dashboard-pi.vercel.app
1•contact_codevia•12m ago•1 comments

GPT-5.4 Thinking System Card

https://openai.com/index/gpt-5-4-thinking-system-card/
6•mudkipdev•12m ago•0 comments

Show HN: Cognitive architecture for Claude Code – triggers, memory, docs

https://github.com/safety-quotient-lab/psychology-agent
1•9wzYQbTYsAIc•15m ago•0 comments

Free $1

https://block-book.com/user/kushalkd
1•blockbook123•15m ago•1 comments

GPT-5.4

https://openai.com/index/introducing-gpt-5-4/
38•meetpateltech•15m ago•6 comments

The Download: an AI agent's hit piece, and preventing lightning

https://www.technologyreview.com/2026/03/05/1133968/the-download-ai-agent-hit-piece-preventing-li...
1•joozio•16m ago•0 comments

Study highlights significant costs in large-scale mechanical thinning of forests

https://phys.org/news/2026-02-highlights-significant-large-scale-mechanical.html
3•PaulHoule•18m ago•0 comments

Reasoning models struggle to control their chains of thought, and that’s good

https://openai.com/index/reasoning-models-chain-of-thought-controllability/
7•meetpateltech•19m ago•0 comments

Urgent: Write the FCC to Oppose SpaceX and Reflect Orbital Plans

https://www.nakedcapitalism.com/2026/03/urgent-please-write-the-fcc-to-oppose-latest-spacex-world...
3•haagen•20m ago•0 comments

Deutschland-Stack: Open-Source Alliance Warns of "Sovereignty Washing"

https://www.heise.de/en/news/Deutschland-Stack-Open-Source-Alliance-warns-of-Sovereignty-Washing-...
4•doener•20m ago•0 comments

Show HN: RuneCast – Visual desktop automation with OpenCV template matching

https://nectra-th.github.io/runecast-releases/
1•ZalaterX•21m ago•0 comments

Using Codex as a Development Partner to Build an Interactive Fiction Platform

https://medium.com/@santi.santamaria.medel/interactive-fiction-platform-codex-ai-093358665827
2•oldskultxo•22m ago•0 comments