frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: What is a passkey and why is everybody asking for one lately?

8•CGMthrowaway•2h ago
As someone with unique passwords, 2FA, email aliases and a decent password manager and I see no real appeal to passkeys. If anything they seem less secure than what I have now. I understand how it’s leaps and bounds better for people that have reused and simple passwords.

However, the "passkeys" branding is pretty much exclusively used for keys that sync, usually with the platform authenticator. Wouldn't that be kind of a big deal, if you were a tinfoil hatter? Am I missing anything?

Comments

runjake•57m ago
Because Passkeys are considered more secure. They had a rough, confusing start but seem to be taking off.

I don't know your level of technical knowledge, but Passkeys are essentially a key pair (public/private) that follows the FIDO2/WebAuthn standard, similar to how PGP, SSH keys, or even website SSL keys work.

The difference here is the private key is stored in a Secure Enclave or a Trusted Platform Module (TPM) on your devices. The Secure Enclave/TPM are theoretically hardware-isolated so that even your OS can't directly access them (no DMA). Instead, you use a special authentication API to make the calls. Again, no direct memory access (unless an exploit is found. :-P)

Normally, you use biometrics or a PIN to provide user verification to the Secure Enclave/TPM, which unlocks access.

Here's how the flow works as I understand it:

1. You visit a website and try to login.

2. The server sends a randomized challenge string.

3. Your device's authenticator signs that challenge using the private key.

4. That signature gets sent back to the server.

5. The server verifies the signature using the public key it has on file.

Why Passkeys are cool:

- No shared secrets, so there's nothing on the server that's useful to steal.

- They're phishing resistant, the browser or whatever ensures the origin matches before allowing auth.

- No replay attacks because the server issues a new randomized challenge string every time.

- No cred stuffing because each passkey is unique to the service it's generated for.

This should all be correct to the best of my unexpert knowledge.

Colleges Face a Reckoning: Is a Degree Really Necessary?

https://www.nytimes.com/2025/10/22/us/value-of-higher-education-attainment-rates-graduation.html
1•bookofjoe•1m ago•1 comments

NASA tested my chain theory in space [video]

https://www.youtube.com/watch?v=NtZaP8VMv0c
1•CGMthrowaway•1m ago•0 comments

Return YouTube Dislike" Chrome Extension Injecting Ads

https://chromewebstore.google.com/detail/return-youtube-dislike/gebbhagfogifgggkldgodflihgfeippi/...
3•snug•4m ago•1 comments

Code Like a Surgeon

https://www.geoffreylitt.com/2025/10/24/code-like-a-surgeon.html
1•speckx•4m ago•1 comments

mRNA Vaccines and Immuno-Oncology: Good News by Derek Lowe

https://www.science.org/content/blog-post/mrna-vaccines-and-immuno-oncology-good-news
2•INGELRII•5m ago•0 comments

Redwood Materials Tops $6B Valuation in Funding Round

https://www.bloomberg.com/news/articles/2025-10-23/redwood-materials-tops-6-billion-valuation-in-...
2•toomuchtodo•7m ago•2 comments

Ask HN: How did you scale AI development?

1•logicallee•7m ago•1 comments

The oldest living things in the world

http://www.rachelsussman.com/oltw
1•lunarbearx•10m ago•0 comments

Early research on economies of scale for computer systems

https://shape-of-code.com/2025/10/05/early-research-on-economies-of-scale-for-computer-systems/
2•oldnetguy•11m ago•0 comments

Use Amp Free at Work

https://ampcode.com/news/amp-free-no-training
1•janpio•11m ago•0 comments

Old Western Digital SMR hard drives have vulnerable firmware

https://www.heise.de/en/news/Risk-of-Defect-Data-Recovery-Specialists-Advise-Backups-of-Older-WD-...
1•NKosmatos•12m ago•1 comments

Ask HN: Why do my friends' users hate the product? Is it worth finding out?

1•helicone•13m ago•1 comments

Automating Oral Argument

https://adamunikowsky.substack.com/p/automating-oral-argument
1•Kaibeezy•14m ago•0 comments

The Coming Clash of Civilizations

https://www.notesfromthecircus.com/p/the-coming-clash-of-civilizations
5•stackbutterflow•17m ago•0 comments

Show HN: Grab elements from your page and give it to AI

1•aidenyb•17m ago•0 comments

Luau's Performance

https://luau.org/performance
1•birdculture•18m ago•0 comments

Ivy League psychologist: 'Bring your whole self to work' is bad advice

https://www.cnbc.com/2025/10/24/bring-your-whole-self-to-work-is-bad-advice-ivy-league-psychologi...
11•donsupreme•19m ago•3 comments

Show HN: I built a Claude Code wrapper to play minigames while its working

https://claude-arcade.lovable.app/
1•FerZu•22m ago•0 comments

Properties and sensory characteristics of new improved nutrition white breads

https://www.sciencedirect.com/science/article/pii/S0023643825009818
1•PaulHoule•22m ago•0 comments

Whitehouse.gov

https://www.whitehouse.gov/about-the-white-house/the-white-house/
5•Teever•23m ago•4 comments

Is there a right way to write?

https://news.harvard.edu/gazette/story/2025/10/is-there-a-right-way-to-write/
2•gnabgib•24m ago•0 comments

Socket Firewall Enterprise: Flexible, Configurable Protection For

https://socket.dev/blog/socket-firewall-enterprise
1•feross•24m ago•0 comments

Ask HN: Security of Hardware Nano KVM

1•WorldDev•26m ago•0 comments

Show HN: Run Claude Skills locally on your Mac (no cloud upload)

https://github.com/instavm/coderunner/blob/main/SKILLS-README.md
1•mkagenius•27m ago•0 comments

Advanced Claude Code Hooks: Controlling Sub-Agent Behavior

https://ltscommerce.dev/articles/claude-code-hooks-subagent-control.html
1•ltsjoe•29m ago•0 comments

Two unsuspected pathogens struck Napoleon's army in 1812

https://www.pasteur.fr/en/press-area/press-documents/study-suggests-two-unsuspected-pathogens-str...
1•geox•33m ago•0 comments

Large Language Muddle

https://www.nplusonemag.com/issue-51/the-intellectual-situation/large-language-muddle/
1•greenie_beans•34m ago•0 comments

Tales from Toddlerhood

https://waitbutwhy.com/2025/10/toddler.html
2•MattSayar•35m ago•0 comments

Show HN: Meds – lock-free Golang firewall using NFQUEUE (net healing)

https://github.com/cnaize/meds
1•cnaize•35m ago•0 comments

Show HN: Convert2PDF API – Convert, Compress, and Capture PDFs and Images

https://convert2pdfapi.com
2•convert2pdfapi•35m ago•0 comments