frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•11mo ago

Comments

palata•11mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Binary GCD

https://gmplib.org/manual/Binary-GCD
1•tosh•6m ago•0 comments

Young sons of legendary U.S. marshal ride horseback from Oklahoma to New York

https://texascooppower.com/the-astonishing-ride-of-the-abernathy-boys/
1•mhb•9m ago•0 comments

Thoughts and Feelings Around Claude Design

https://samhenri.gold/blog/20260418-claude-design/
1•cdrnsf•10m ago•0 comments

OpenAI Proposes a 'Social Contract' for the Intelligence Age

https://www.noemamag.com/openai-proposes-a-social-contract-for-the-intelligence-age/
1•Brajeshwar•11m ago•0 comments

Show HN: TTS.ai

https://tts.ai/
1•nadermx•11m ago•0 comments

My personal website – a start to my internet home

https://alexarias.me/
1•AlexArias•11m ago•0 comments

Vibe Genomics: Sequencing Your Whole Genome at Home

https://vibe-genomics.replit.app/
1•moozilla•12m ago•0 comments

Show HN: Trained a 12M transformer on an ML framework we built from scratch

https://github.com/mni-ml/framework
1•caliandbust•12m ago•0 comments

Trappsec – Deception as a Developer Tool

https://trappsec.dev
2•kyuradar•15m ago•1 comments

Open Source SaaS Is Dead, AI Killed It

https://nmn.gl/blog/open-source-killed-ai
1•namanyayg•15m ago•0 comments

Claude –dangerously-skip-permissions –model Claude-Opus-4-5-20251101

1•deofoo•18m ago•0 comments

Salesforce Goes Headless: The Smart Self-Disruption Play

https://www.whatshotit.vc/p/whats-in-enterprise-itvc-494
1•jhonovich•18m ago•0 comments

The Best Sports Game Nobody Played [video]

https://www.youtube.com/watch?v=7cMc4M5QJvM
1•pulkitsh1234•21m ago•0 comments

Our World in Data

https://ourworldindata.org
2•dnw•22m ago•0 comments

Version 1.0 Released: WireGuard for Windows and WireGuardNT

https://lore.kernel.org/wireguard/CAHmME9pDd2JMcEuSgOKpXPhUB8FSO+rNJdTkXRzpLhK1_xW9Cg@mail.gmail....
2•zx2c4•23m ago•0 comments

Ask HN: Stable, self-hosted macOS VFS that works in 2026?

1•buibuibui•24m ago•0 comments

A short quest to build some Web Feeds

https://lzon.ca/posts/site/feeds/
1•jpmitchell•24m ago•0 comments

Scopeon – AI Observability – token breakdown, cache ROI, cost tracking, CI gates

https://github.com/sorunokoe/Scopeon
3•sorunokoe•25m ago•0 comments

(Gated) Secure Coding AI Prompt Library

https://newsletter.shehackspurple.ca/c/securemyvibe
1•shehackspurple•25m ago•1 comments

How the UK Retreated on Cloud and Called Its Local Media Band-Aid a Plan

https://www.techpolicy.press/how-the-uk-retreated-on-cloud-and-called-its-local-media-bandaid-a-p...
2•ripe•27m ago•0 comments

The blast radius problem with coding agents in bypass mode

https://www.arnaudp.dev/the-blast-radius-problem-running-your-coding-agent-in-yolo-mode/
1•gentle_bubble•28m ago•0 comments

College instructor turns to typewriters to curb AI-written work

https://sentinelcolorado.com/uncategorized/a-college-instructor-turns-to-typewriters-to-curb-ai-w...
2•gnabgib•29m ago•0 comments

Adobe Has Run Out of Allies

https://petapixel.com/2026/04/18/adobe-has-run-out-of-allies/
3•MBCook•33m ago•0 comments

50% of AI datacenters have been cancelled or "delayed"

https://www.youtube.com/watch?v=w-DVTHH1ux8
4•amanaplanacanal•36m ago•0 comments

Widgetfied: Multi-tenant widget platform and hosted pages for service businesses

https://widgetfied.com
1•guymorganb•37m ago•0 comments

Digital Ecosystems: Interactive Multi-Agent Neural Cellular Automata

https://pub.sakana.ai/digital-ecosystem/
2•SebastianSosa•38m ago•0 comments

What Emotion Goes Viral the Fastest? (2014)

https://www.smithsonianmag.com/science-nature/what-emotion-goes-viral-fastest-180950182/
1•chistev•41m ago•1 comments

Music discovery that works like flipping through record store bins

https://app.vinylbins.com/
1•dclatfel•42m ago•0 comments

Deep Scan Page Reader WCAG 2.2 Accessibility

https://webpossum.com
1•raphaelheide•43m ago•0 comments

How Are Calories in Foods Measured?

https://www.merckmanuals.com/home/multimedia/table/how-are-calories-in-foods-measured
1•georgecmu•44m ago•0 comments