frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

EchoPitch analyses emotional credibility in presentations before you deliver

https://echopitch.io
1•cavefishAI•31s ago•0 comments

Ask HN: Is Java the ideal language for LLM-assisted coding?

1•fragmede•31s ago•0 comments

New Design for the FreeBSD Website

https://cgit.freebsd.org/doc/commit/?id=c9c518d9dbb70240c23810f300ce4a5ba60442c6
1•vintagedave•1m ago•1 comments

Nobody's negotiating for the people here: Charlie Berens takes on AI datacenters

https://www.theguardian.com/us-news/ng-interactive/2026/may/17/comedian-charlie-berens-ai-datacen...
1•beardyw•2m ago•0 comments

Electric Clojure: Differential Dataflow for UI [video]

https://www.youtube.com/watch?v=ML8cFrWkWeg
1•farhanhubble•2m ago•0 comments

AI Foundry – Flat-Fee Unlimited LLM Inference on Blackwell GPUs in NZ

https://app.aifoundry.co.nz/auth/login?redirectTo=%2F
1•itsjpv•2m ago•0 comments

TechForges – Zero-Infra Software via Flux AI and Vibe-Mesh

https://sites.google.com/view/techforges/
1•SharavFounder•2m ago•0 comments

Human Code Reviews Are Dead

https://craftbettersoftware.com/p/human-code-reviews-are-dead
1•TheAnkurTyagi•7m ago•0 comments

OpenClaw creator burns through $1.3 mio in OpenAI API tokens in a single month

https://www.tomshardware.com/tech-industry/artificial-intelligence/openclaw-creator-burns-through...
2•m0do1•9m ago•0 comments

The Mercury logic programming system

https://github.com/Mercury-Language/mercury
1•Antibabelic•11m ago•0 comments

AI Won't Run Your Company by Itself

https://www.caimito.net/en/blog/2026/05/18/ai-wont-run-your-company-by-itself.html
3•berlianta•13m ago•0 comments

Grills and Smokers of 2026: Smart, Portable, Pellet

https://www.wired.com/story/best-grills-and-smart-grills/
1•joozio•13m ago•0 comments

Why the Spotify icon is a disco ball

https://mashable.com/article/spotify-disco-ball-icon-20-anniversary
1•doppp•14m ago•0 comments

Surprise AI bills leave AWS and Google Cloud users aghast

https://www.theregister.com/ai-ml/2026/05/18/surprise-ai-bills-leave-aws-and-google-cloud-users-a...
4•medalblue•15m ago•0 comments

Designskill.co

https://designskill.co/
2•anoopbln•19m ago•0 comments

Slimbook Linux Laptops

https://slimbook.com/en/
1•maelito•24m ago•0 comments

How to Think About AI in Your Product

https://abgoyal.com/posts/how-to-think-about-ai-in-your-product/
1•ghoul2•25m ago•0 comments

Dots and Boxes – real-time multiplayer, no signup

https://dotsandboxes.aeonic.earth/
1•AmartyaMandal•31m ago•0 comments

Curated list of resources on testing distributed systems

https://github.com/asatarin/testing-distributed-systems
2•jinqueeny•33m ago•0 comments

GateGraph – deterministic governance for AI agents

https://github.com/humancoreai/Gategraph
1•humancore•38m ago•0 comments

How to Learn Agentic AI in 2026 – Without Getting Lost in Hype

https://simplai.ai/blogs/how-to-actually-learn-agentic-ai-in-2026/
3•shanmugarajsk•39m ago•0 comments

I put Codex and Claude into a tank arena. Codex is winning 55% so far

https://old.reddit.com/r/codex/comments/1tgbb28/comment/omfo1by/
2•mazzystar•53m ago•0 comments

KiviDB – In Memory Store

https://kividb.io/
1•_nvp•55m ago•0 comments

Nobody understands the point of hybrid cars [video]

https://www.youtube.com/watch?v=KnUFH5GX_fI
1•CHB0403085482•56m ago•0 comments

Show HN: A CLI command to test internet speed

https://pypi.org/project/tracerate
1•rushil_b_patel•59m ago•0 comments

Litterbox: Somewhat Isolated Development Environments [video]

https://www.youtube.com/watch?v=OMCWs7qmKFc
1•Gerharddc•59m ago•1 comments

I built an AI vulnerability scanner with Claude and Codex. It failed

https://github.com/janitor-security/the-janitor
1•GhrammR•1h ago•0 comments

RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields

https://neurowinter.com/security/2026/05/18/RCE-and-arbitrary-file-write-in-Vitess-vtbackup-via-u...
1•NeuroWinter•1h ago•0 comments

The Infinite Policeman – Preliminary Movement

https://medium.com/luminasticity/the-infinite-policeman-preliminary-movement-5038a293c1f2
2•bryanrasmussen•1h ago•0 comments

Playing with Jupyter style playbooks that work with Claude Code

https://old.reddit.com/r/ClaudeCode/comments/1tgdvex/playing_with_jupyter_style_playbooks_that_work/
2•bgnm2000•1h ago•0 comments