frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

I Put ChatGPT Browser Inside My Terminal [video]

https://www.youtube.com/watch?v=YErIWOPytuc
1•tomerbd•39s ago•0 comments

The Wrath of the Killdozer (2009)

https://www.damninteresting.com/the-wrath-of-the-killdozer/
1•bookofjoe•1m ago•0 comments

Data Centers Have a New Adversary: Tigers and Leopards at a Zoo

https://www.bloomberg.com/news/articles/2026-06-05/data-centers-have-a-new-adversary-tigers-and-l...
1•1vuio0pswjnm7•2m ago•0 comments

Amazon Employees Show Up to City Council Meetings, Demand Limits on Data Centers

https://www.wired.com/story/amazon-employees-publicly-demand-regulations-on-data-centers/
2•1vuio0pswjnm7•4m ago•0 comments

We Built Plainform and What It Means for Your Next Project

https://plainform.dev
1•eradon•4m ago•0 comments

Transformers Are Inherently Succinct

https://openreview.net/pdf?id=Yxz92UuPLQ
1•brandonb•4m ago•0 comments

Jax Back Ends and Devices

https://www.gilesthomas.com/2026/06/jax-backends-and-devices
1•gpjt•5m ago•0 comments

Tech sovereignty package to strengthen Europe's digital autonomy and resilience

https://ec.europa.eu/commission/presscorner/home/en
1•andrewstetsenko•5m ago•0 comments

Show HN: SupXML, modern memory-safe XML parser replacement for libxml2

https://supso.org/projects/sup-xml/docs
1•jrpt•6m ago•0 comments

Against an Increasingly User-Hostile Web (2017)

https://neustadt.fr/essays/against-a-user-hostile-web/
2•arunc•10m ago•0 comments

Pasteur, a zero-knowledge pastebin as an unikernel in OCaml

https://github.com/dinosaure/pasteur
1•dinosaure•13m ago•0 comments

Employees aren't resisting AI – they're resisting fear

https://www.fastcompany.com/91541703/employees-arent-resisting-ai-theyre-resisting-fear-ai-employ...
1•berlianta•14m ago•0 comments

OpenClaw Got Safer in Public

https://openclaw.ai/blog/openclaw-security-in-public
1•cryptoking1106•15m ago•0 comments

Digital Dead Man's Switch for Your Files

https://trustbourne.com/
1•BerislavLopac•15m ago•0 comments

What is my IP address?

https://ip.hny.io
1•astrochicken•17m ago•0 comments

Show HN: Lazarus, a coding agent for long-horizon tasks

https://github.com/ExpressGradient/lazarus
1•Sai_Praneeth•17m ago•0 comments

Are Memories Transferable – Or Edible?

https://www.quantamagazine.org/are-memories-transferable-or-edible-20260605/
2•kiwicopple•18m ago•0 comments

AI enthusiasts race against time, AI skeptics race against entropy

https://charity.wtf/2026/06/02/ai-enthusiasts-are-in-a-race-against-time-ai-skeptics-are-in-a-rac...
2•BerislavLopac•19m ago•0 comments

Why Can't California Count?

https://www.natesilver.net/p/why-cant-california-count
2•7777777phil•19m ago•0 comments

Neocities domain suspended by Namecheap for unrelated court case

https://bsky.app/profile/neocities.org/post/3mnkqgxostk2k
7•ScrapBlox•19m ago•0 comments

The Fitbit Air is a good wearable weighed down by a chatty AI "coach"

https://arstechnica.com/gadgets/2026/06/the-fitbit-air-is-great-but-googles-ai-is-too-nice-to-be-...
2•canucker2016•21m ago•0 comments

Assessing the Effect of a Deep-Rooted Grass on Belowground Carbon Storage

https://agupubs.onlinelibrary.wiley.com/doi/10.1029/2025EF007102
1•PaulHoule•22m ago•0 comments

How Not to Die (2007)

https://paulgraham.com/die.html
1•downbad_•22m ago•0 comments

Aging and Eye Problems

https://ldstephens.net/posts/aging-and-eye-problems/
3•speckx•24m ago•0 comments

Building the Tampermonkey Replacement

https://www.youtube.com/watch?v=bvv3bYf-6ik
2•jobello•25m ago•1 comments

Reverse Engineering Crazy Taxi, Part 3

https://wretched.computer/post/crazytaxi3
3•wgreenberg•27m ago•0 comments

MS Sharepoint sunset of "Alert me" (on folder changes) completes next month

https://techcommunity.microsoft.com/blog/spblog/sharepoint-alerts-retirement/4410402
2•realityfactchex•27m ago•1 comments

Official Invitation to the Beta Test: "Knowledge in a Box"

https://sozialsoziokrat.substack.com/p/official-invitation-to-the-beta-test
2•Daniel_Bauer•30m ago•0 comments

Data Viz and Table Design from the Letterpress Era

https://chris-parmer.com/data-viz-from-the-letterpress-era/
1•robertclaus•32m ago•0 comments

Reviewing Code Requires Reading

https://hauleth.dev/post/review-requires-reading/
2•birdculture•33m ago•0 comments