frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•10mo ago

Comments

palata•10mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Generative AI Vegetarianism

https://sboots.ca/2026/03/11/generative-ai-vegetarianism/
1•g-b-r•3m ago•0 comments

Creaseless Foldable: Oppo Did What Samsung Couldn't [video]

https://www.youtube.com/watch?v=V5a6qvETnNg
1•mgh2•4m ago•0 comments

Show HN: A public RSS feed aggregator for the indie web

https://powrss.com/
2•nyoki•6m ago•0 comments

OpenUI: Open Standard for Generative UI

https://www.openui.com/
1•handfuloflight•6m ago•0 comments

RSA Innovation Sandbox finalists for 2026

https://www.rsaconference.com/usa/programs/innovation-sandbox
2•debarshri•9m ago•0 comments

Ask HN: What software has improved dramatically recently thanks to AI tooling?

1•pedrodelfino•9m ago•0 comments

The Death of the Downvote

https://nathankyoung.substack.com/p/the-death-of-the-downvote
1•bookofjoe•11m ago•0 comments

Hedystia – Next-Gen TypeScript Framework for Type-Safe APIs at Lightspeed

https://github.com/Hedystia/Framework
1•Zastinian•11m ago•1 comments

Proposal: Global Solar-Offset Fractional Time (G-Soft) Model

1•4TimeSake•11m ago•0 comments

Physical Laser Art

https://www.youtube.com/channel/UCJUV-vrFg0DI7nq-rbWkhGw
1•unit-vector•15m ago•0 comments

PlayStation gamers could receive £2B compensation if lawsuit succeeds

https://news.sky.com/story/playstation-gamers-could-receive-2bn-compensation-if-lawsuit-succeeds-...
3•Brajeshwar•17m ago•1 comments

EU Parliament: MEPs Vote to End Untargeted Mass Scanning of Private Chats

https://www.patrick-breyer.de/en/historic-chat-control-vote-in-the-eu-parliament-meps-vote-to-end...
3•anigbrowl•20m ago•1 comments

Shell declares force majeure to clients who buy Qatari LNG

https://www.reuters.com/business/energy/shell-totalenergies-others-declare-fm-their-clients-who-t...
2•geox•21m ago•0 comments

We built a lean, high-perf dashboard for Yeahchain

1•YeahchainTECH•22m ago•0 comments

Veil of Ignorance

https://en.wikipedia.org/wiki/Original_position
2•sillywabbit•23m ago•0 comments

New course on generative AI for behavioral science

https://statmodeling.stat.columbia.edu/2026/03/10/new-course-on-generative-ai-for-behavioral-scie...
1•dlojudice•27m ago•0 comments

Google sells partial stake in fiber, becomes minority owner of new venture

https://www.cnbc.com/2026/03/11/google-sells-partial-stake-in-fiber-becomes-minority-owner-in-ven...
3•internet-390•27m ago•0 comments

ICE/DHS gets hacked, all Contractors exposed

https://micahflee.github.io/ice-contracts/
3•peq42•31m ago•0 comments

Scaling the Lexinova Data Pipeline

1•LEXINOVAFaqs•33m ago•0 comments

Microsoft's growing control of Linux (2022)

https://lunduke.substack.com/p/microsofts-growing-control-of-linux
3•totetsu•34m ago•0 comments

Urea prices

https://tradingeconomics.com/commodity/urea
42•burnt-resistor•34m ago•21 comments

Collecting perceptual data for a possible CSS optical-center property

1•gorkemyildiz•35m ago•0 comments

The Department of War is making a mistake [video]

https://www.youtube.com/watch?v=KBPOTklFTiU
2•ipnon•38m ago•0 comments

How do you handle state persistence in non-orientable data structures?

https://zenodo.org/records/18942850
1•MareSerenitatis•39m ago•1 comments

What happens if OpenAI or Anthropic fail?

https://www.reuters.com/commentary/breakingviews/what-happens-if-openai-or-anthropic-fail-2026-03...
6•billybuckwheat•40m ago•3 comments

Ask HN: Is Github Down Again?

https://twitter.com/m0nle0z/status/2031910716790517895
3•doanbactam•41m ago•5 comments

Why America Is Losing the War with Iran

https://chrishedges.substack.com/p/why-america-is-losing-the-war-with
8•chmaynard•42m ago•0 comments

I made a Chrome extension to export an entire Gemini chat

2•backrun•42m ago•0 comments

10 Years Later, I Reverse-Engineered iCloud's SyncToken by Brute Force

https://robhooper.xyz/blog-synctoken.html
2•rhoopr•43m ago•0 comments

Scalable quantum batteries can charge faster than their classical counterparts

https://phys.org/news/2026-03-scalable-quantum-batteries-faster-classical.html
1•Brajeshwar•44m ago•0 comments