frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Passwords are okay, impulsive Internet isn't

https://www.dedoimedo.com/life/passwords-passkeys.html
3•brycewray•1y ago

Comments

palata•1y ago
Hmm... I see a rant against the state of software (bad software, AI diarrhea, ...) and TooBigTech having control over everything. I can agree with that, but it has nothing to do with the "passwords vs passkeys" question.

The rant against passkeys? I don't get it. Just like one can use a password manager controlled by TooBigTech or KeePass, one can use a passkey controlled by TooBigTech or a Yubikey. I find it great to authenticate directly with my Yubikey (over FIDO2) instead of using my Yubikey to decrypt a password and copying it in a form.

And then there is the part that is completely wrong about security. They say that they "can't trust their phone" so they don't want to keep the passkeys there. But that is not correct: if the passkeys are encrypted and the key is stored in a TPM, then that's effectively similar to having a security key (you have to trust the TPM, just as you have to trust the security key of course).

And then there is the nonsense:

> I can set up KeePass Portable on a USB key, run it in Linux via WINE, place it inside an encrypted VeraCrypt container, copy to any which file sharing service, if I want.

If the device where you enter the password is compromised, then the password will be compromised as soon as you enter it on that device. No matter how much you show off with your funny setup with WINE and VeraCrypt. A password manager doesn't protect against that, so passwords can be exfiltrated as they are used. Whereas a FIDO2 authentication requires the passkey every time. E.g. I need to physically touch my Yubikey for it to sign the challenge. It could be MitM, but it is visible ("I touched my Yubikey and it didn't work, what happened?").

Authenticating over FIDO2 with a security key is strictly superior to entering a password in a field, period.

The Weight-Loss Revolution People Didn't Want

https://greyenlightenment.com/2026/06/23/the-weight-loss-revolution-people-didnt-want/
1•paulpauper•5m ago•0 comments

Show HN: KV-psi, using Linux PSI to to trim an LLM KV cache

https://github.com/infiniteregrets/kv-psi
1•infiniteregrets•6m ago•0 comments

The psychology behind AI fueled delusions

https://www.wsj.com/tech/personal-tech/ai-chatbots-psychology-delusion-662a3663
1•Jimmc414•6m ago•1 comments

Show HN: Peek-CLI: let coding agents see your browser

https://github.com/puffinsoft/peek-cli
3•BeverlyHills001•6m ago•0 comments

Show HN: Sasso – pure-Rust SCSS compiler, byte-exact to current dart-sass

https://github.com/momiji-rs/sasso
1•linyiru•6m ago•0 comments

Walter S. Arnold–Sculptor/Stone Carver

https://stonecarver.com/
1•NaOH•8m ago•0 comments

Reserved THP Feature Proposed for Linux to Combine the Best of HugeTLB and THP

https://www.phoronix.com/news/Reserved-THP-Linux
1•Bender•16m ago•0 comments

How to Audit a Legacy Codebase in the First Week

https://piechowski.io/post/how-i-audit-a-legacy-rails-codebase/
1•howToTestFE•17m ago•0 comments

Graphify – Open-Source Knowledge Graph Skill for AI Coding Assistants

https://graphify.net/index.html#features
1•xy008areshsu•30m ago•0 comments

US Army used 35 drones and 100 lb of C4 to clear a breach

https://www.businessinsider.com/us-army-commander-used-drones-c4-packed-robots-clear-breach-2026-6
2•Lihh27•31m ago•0 comments

Set Up Your Own DoH Service

https://nochan.net/b/Internet-Crap/20260602-Set-Up-Your-Own-DoH-Service/
2•Bender•32m ago•0 comments

Show HN: I made a webcam motion detector, local/cloud storage, AI person detect

https://camera10.com/
1•pixeltwenty•32m ago•0 comments

Tesla settles lawsuit over fatal FSD pedestrian crash tied to 3.2M-vehicle probe

https://electrek.co/2026/06/26/tesla-fsd-pedestrian-death-settlement/
3•logickkk1•36m ago•0 comments

Old Computer Challenge

http://occ.sdf.org/
1•wrxd•38m ago•0 comments

Show HN: Vlt – A local vault for the API keys you use in every project

https://bwanaerp.medium.com/how-to-stop-losing-api-keys-forever-i-built-a-tool-for-this-8b2adfca782a
1•instarlaxy•40m ago•0 comments

The cost YAGNI was never about

https://newsletter.kentbeck.com/p/the-cost-yagni-was-never-about
1•mustaphah•42m ago•0 comments

Choosing a Public DNS Resolver

https://evilbit.de/dns-resolver-guide.html
1•pawal•45m ago•0 comments

Show HN: E3d-pod2vid – AI pipeline that turns podcasts into YouTube-ready videos

https://github.com/spacepacket1/e3d-pod2vid
2•spacepacket•47m ago•0 comments

Heimdall, a small open-source TUI to watch my homelab machines from one terminal

https://github.com/kinncj/Heimdall
2•kinncj•49m ago•0 comments

Why One of Tech's Biggest Gamblers Is Betting Against Elon Musk's AI Vision

https://www.wsj.com/tech/why-one-of-techs-biggest-gamblers-is-betting-against-elon-musks-ai-visio...
3•1vuio0pswjnm7•50m ago•4 comments

Reclaiming the Roads

https://worksinprogress.co/issue/reclaiming-the-roads/
2•JumpCrisscross•52m ago•0 comments

Silicon Valley has much to learn from the spreadsheet jockeys it despises

https://www.economist.com/business/2026/06/24/silicon-valley-has-much-to-learn-from-the-spreadshe...
2•1vuio0pswjnm7•53m ago•0 comments

GPS Satellites Tracker

https://www.gps-satellites.com/
1•ohjeez•57m ago•0 comments

HackMate – Automate the OpenCore Hackintosh USB Setup from Linux/Windows/macOS

https://github.com/riftaway7-code/hackmate
1•hackmateapp•58m ago•0 comments

jQuery 4.0 Performance

https://www.mida.so/blog/jquery-is-slow
2•okozzie•59m ago•0 comments

Show HN: Claude-CLI – Run Claude Code in a throwaway Docker container

https://github.com/shirozuki/claude-cli
1•shirozuki•1h ago•0 comments

Show HN: Starglyphs - A constellation puzzle game based on Euler paths

https://starglyphs.com
2•telman17•1h ago•0 comments

YimbyTown '26 – The National Pro-Housing Conference

https://yimby.town/
1•JumpCrisscross•1h ago•0 comments

Hyperphantasia

https://en.wikipedia.org/wiki/Hyperphantasia
6•cl3misch•1h ago•1 comments

Michigan spent $1.8B and only created 602 jobs

https://www.msn.com/en-us/money/general/michigan-spent-1-8-billion-and-only-created-602-jobs/ar-A...
35•littlexsparkee•1h ago•9 comments