frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•6mo ago

Comments

palata•6mo ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

Memories of .us

https://computer.rip/2025-11-11-dot-us.html
1•todsacerdoti•1m ago•0 comments

How I talk to whales

https://www.nytimes.com/2025/11/23/opinion/whale-language-ai.html
2•flabber•1m ago•0 comments

Show HN: I wrote my lecture notes in Typst

https://github.com/zhengnanli/ss-notes
2•subtlemuffins•2m ago•0 comments

Turbine Transport Transformer

https://mitxela.com/projects/turbine_transport_transformer
1•mhb•2m ago•0 comments

Kubricks' 2001: One Man's Incredible Odyssey (2015)

http://nzpetesmatteshot.blogspot.com/2015/01/kubricks-2001-one-mans-incredible.html
1•exvi•3m ago•0 comments

Mind-altering 'brain weapons' no longer only science fiction, say researchers

https://www.theguardian.com/world/2025/nov/22/mind-altering-brain-weapons-no-longer-only-science-...
1•zdw•3m ago•0 comments

Magicians of the Miniature (2014)

http://nzpetesmatteshot.blogspot.com/2014/12/magicians-of-miniature.html
1•exvi•5m ago•0 comments

I built a $19 forensic ATS scanner because Jobscan costs $50/mo

https://www.interviewghost.us/
1•ryanpedram•5m ago•1 comments

Video posted by Garry Tan shows suspect who robbed his friend of $11M in crypto

https://www.sfchronicle.com/crime/article/sf-cryptocurrency-robbery-21203804.php
2•markerz•5m ago•0 comments

Show HN: I built a CLI to use devcontainers without VS Code

https://github.com/UPwith-me/Container-Maker
2•DEVINHE111•8m ago•0 comments

Mitigating Application Resource Overload with Targeted Task Cancellation

http://muratbuffalo.blogspot.com/2025/11/mitigating-application-resource.html
1•zdw•8m ago•0 comments

Unpaid Labor Allegations Cast Shadow over Naver WEBTOON's Market Dominance

https://www.animenewsnetwork.com/feature/2025-11-05/unpaid-labor-allegations-cast-shadow-over-nav...
1•PaulHoule•8m ago•0 comments

Through the Looking Glass: The Traditional Glass Shot Matte Painting (2016)

http://nzpetesmatteshot.blogspot.com/2016/08/through-looking-glass-traditional-glass.html
1•exvi•8m ago•0 comments

Eggroll: Novel general-purpose machine learning algorithm provides 100x speed

https://eshyperscale.github.io/
1•felineflock•10m ago•0 comments

Astrl– a free AI-powered Khan Academy for self-guided learning

https://tryastrl.com/
1•jjwilkin•25m ago•1 comments

We're Stuck in an Infinite Loop of Terrible Tech

https://timyc.substack.com/p/were-stuck-in-an-infinite-loop-of
3•TimDotC•25m ago•1 comments

An Auto Holy Grail: Motors That Don't Rely on Chinese Rare Earths

https://www.nytimes.com/2025/11/24/business/automakers-rare-earth-minerals-magnets.html
1•mmooss•26m ago•0 comments

Anthropic introduces cheaper, more powerful, more efficient Opus 4.5 model

https://arstechnica.com/ai/2025/11/anthropic-introduces-opus-4-5-cuts-api-pricing-and-enables-muc...
1•jnord•28m ago•1 comments

Humanoid robot walked 66 miles in 3 days, right into the Guinness World Records

https://www.cbsnews.com/news/china-humanoid-robot-agibot-a2-walks-66-miles-guinness-world-records/
1•satonakamoto•28m ago•1 comments

Jakarta overtakes Tokyo as largest city, according to UN

https://www.abc.net.au/news/2025-11-25/jakarta-overtakes-tokyo-as-worlds-largest-city/106049122
2•Gaishan•29m ago•1 comments

Endogenous Automation Will Hit You

https://lydianottingham.substack.com/p/endogenous-automation-will-hit-you
1•eatitraw•31m ago•1 comments

Revolut hits $75B valuation

https://news.crunchbase.com/fintech/revolut-valuation-spikes-secondary-share-sale/
2•rudderdev•32m ago•3 comments

Beddel: Secure, Declarative, and Extensible Agent Runtimes

https://github.com/botanarede/beddel-alpha
1•mesenga•32m ago•1 comments

The 'S&P 493' reveals a different U.S. economy

https://www.washingtonpost.com/business/2025/11/24/sp500-stock-market-tech-nvidia/
2•ProAm•36m ago•0 comments

The Valley of Death: Why $100k Is the New Poverty

https://www.thefp.com/p/why-do-americans-feel-poor-because
3•mhb•37m ago•0 comments

Claude Opus 4.5, and why evaluating new LLMs is increasingly difficult

https://simonw.substack.com/p/claude-opus-45-and-why-evaluating
1•hackthegibson2•37m ago•0 comments

Google Further Encroaches on Nvidia's Turf with New AI Chip Push

https://www.theinformation.com/articles/google-encroaches-nvidias-turf-new-ai-chip-push
2•JumpCrisscross•37m ago•2 comments

Real-world Nausicaa Ghibli anime glider completes its final flight in Japan

https://soranews24.com/2025/11/20/real-world-nausicaa-ghibli-anime-glider-completes-its-final-fli...
1•thunderbong•37m ago•0 comments

ULTIMATE EROS 3: An End to Fuckening

https://substack.com/home/post/p-179390401
1•eatitraw•38m ago•0 comments

The Tree That Produces the Only True Blue Fruit on the Planet

https://www.forbes.com/sites/scotttravers/2025/11/23/meet-the-tree-that-produces-the-only-true-bl...
1•malshe•42m ago•1 comments