frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: Nexa-gauge – Cache/cost-aware graph-based eval for LLM and RAG

https://github.com/harnexa/nexa-gauge
1•Sardhendu•5m ago•0 comments

Venom and Hot Peppers Offer a Key to Killing Resistant Bacteria

https://www.wired.com/story/mexican-science-transforms-scorpion-venom-and-habanero-chile-into-ant...
1•littlexsparkee•9m ago•1 comments

Accelerator Applicant's AI System Makes Faux Pau; Critical of Accelerator Model

https://news.novonavis.com/news/intel_080526_2297
1•capagg•13m ago•1 comments

Show HN: Launch and Run Companies on Autopilot

https://lakyus.com/live
1•edonnie•14m ago•1 comments

Claude FM music for thinking and building [video]

https://www.youtube.com/watch?v=AUQKjgKQF7w
1•davidk42•15m ago•0 comments

CVE-2026-7413: Persistent undocumented backdoor access with Yarbo

https://takeonme.org/cves/cve-2026-7413/
1•shakna•16m ago•0 comments

AI Canasta Scoring App

https://canastascore.com/
1•alohaplannerapp•18m ago•0 comments

Playing Around with OpenAI's GPT Realtime Voice API

https://nathancooper.io/blog/2026-05-08-gpt-realtime-audio
1•coop57•21m ago•0 comments

Show HN: AI-native tech assessments (end of LeetCode)

https://www.openround.ai/
2•vetted_so•23m ago•0 comments

The Big Engine That Could

https://medium.com/human-offset/the-big-engine-that-could-de152076bb82
1•gdessau•24m ago•0 comments

Archive.today Reverts to Monero-Only Donations

https://archive.fo
1•Cider9986•25m ago•1 comments

Opentype.js 2.0.0 Released

https://github.com/opentypejs/opentype.js/releases/tag/2.0.0
1•ILOVEPIE•25m ago•0 comments

Dirty Frag Linux kernel local privilege escalation vulnerability mitigations

https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available
2•zajio1am•25m ago•0 comments

Show HN: MOG Simulator, Emergent galaxies via ensemble of grids [video]

https://github.com/tbmo/mog-solver
1•tbmo•25m ago•1 comments

X A "Clean Room" for 2026 technical and logistical news

https://xreport.news/
1•XREPORTNEWS•27m ago•0 comments

James Schuyler's Genius

https://yalereview.org/article/james-schuylers-genius
1•Thevet•27m ago•0 comments

A Robot Just Became a Monk at a Buddhist Temple in South Korea

https://www.smithsonianmag.com/smart-news/meet-gabi-the-new-robot-monk-at-a-buddhist-temple-in-so...
1•lisper•29m ago•0 comments

Loom -single line install TTY IDE for agent coding

https://github.com/claytantor/loom-tty-ide
1•claydronze•30m ago•1 comments

Porn website at center of CNN investigation into sexual abuse taken offline

https://www.cnn.com/2026/05/08/europe/porn-site-motherless-taken-down-dutch-authorities-intl
1•NDlurker•32m ago•1 comments

Jane Street earned $10B in first quarter as it doubled trading revenue

https://www.ft.com/content/fe483e68-097a-4b80-ad3a-0792dda8f94a
2•KnuthIsGod•33m ago•0 comments

I built a pixel oven that tells you if you're cooked

https://broamicooked.com/
1•HealthAI47•35m ago•0 comments

Ask HN: What are the most joyful AI projects you've seen?

3•adagradschool•36m ago•1 comments

San Francisco's housing market has lost its mind

https://techcrunch.com/2026/05/08/san-franciscos-housing-market-has-lost-its-mind/
1•littlexsparkee•39m ago•0 comments

Iran war's global energy crisis sharpens China's advantage in clean tech

https://apnews.com/article/iran-middle-east-war-energy-asia-china-05d198d6e8dc99d0209dddfff26ae52a
4•breve•46m ago•0 comments

Reduce friction and latency for long-running jobs with Webhooks in Gemini API

https://twitter.com/GoogleAIStudio/status/2051421109506228656
1•gmays•52m ago•0 comments

Pushing Local Models with Focus and Polish

https://lucumr.pocoo.org/2026/5/8/local-models/
1•wrxd•54m ago•0 comments

Show HN: [Video] Tribute to LLM releases in April 2026

https://www.youtube.com/watch?v=uu5ffMH_X9w
2•everlier•58m ago•0 comments

The FCC Wants Your ID Before You Get a Phone Number

https://reclaimthenet.org/the-fcc-wants-your-id-before-you-get-a-phone-number
8•bilsbie•1h ago•1 comments

You Might Be a Late Bloomer (2024)

https://www.theatlantic.com/ideas/archive/2024/06/successs-late-bloomers-motivation/678798/
2•breve•1h ago•0 comments

The Tax of Living in a Low-Trust Society: How Collapsed Trust Costs You

https://yourbrainonmoney.substack.com/p/low-trust-society-cost
23•ot•1h ago•9 comments
Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.