frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Ask HN: Why aren't hardware passkeys used for access token creation?

2•zackify•1h ago
So I was thinking, with all these sophisticated attacks on package managers, that I should use a yubikey more.

One problem I wanted to solve for myself, is that each morning, open my fine grained access token tab on github, regenerate the key for the gh cli with 1 day expiry.

Paste this into my small cli wrapper, and now even if someone gained access to my filesystem, my private key is on the hardware key, my gh cli token will expire shortly.

It got me thinking, why isnt there CLI level fido2 support for common AI services and github for example?

Instead of a long lived key when you open claude, why can't it just require a touch of the hardware key, generate a temporary 1 hour key for use.

Claude / Github only has the hardware public key and any attack stealing any keys can not do much damage.

Instead to do this workflow right now, I have to manually open their site (login via passkey on the ones that support it), and regen a key with short expiry, and paste back to tool.

Existential Threat or Leverage: Your Choice

https://graybearding.bearblog.dev/existential-threat-or-leverage-your-choice/
1•rglover•1m ago•0 comments

The high-profile contest to explain Einstein

https://physicstoday.aip.org/news/the-high-profile-contest-to-explain-einstein
1•tzury•1m ago•0 comments

We Built Laravel Cloud's Scale to Zero

https://laravel.com/blog/how-we-built-laravel-clouds-scale-to-zero
1•AnhTho_FR•2m ago•0 comments

Show HN: An AI resume tool that never invents experience you didn't have

https://hiredcopilot.com
1•Xotic007•3m ago•0 comments

US agency removes Chinese toy drones from import ban list

https://www.reuters.com/world/us/us-agency-removes-chinese-toy-drones-import-ban-list-2026-06-16/
1•onemoresoop•5m ago•0 comments

Show HN: Alternative way to do remote codex via NovaScale with builtin Tailscale

https://apps.apple.com/us/app/novascale-built-for-tailscale/id6749938291
1•mintflow•5m ago•0 comments

The New SDLC with Vibe Coding

https://www.kaggle.com/whitepaper-the-new-SDLC-with-vibe-coding
1•simonpure•5m ago•0 comments

After AI Takes Everything

https://ursb.me/en/posts/after-ai-takes-everything/
1•speckx•6m ago•0 comments

A 10-KB model that decides when a 4B-parameter robot policy wakes up

https://huggingface.co/spaces/Kaikaku/aegis-demo
1•josefchen•7m ago•0 comments

Leading Deepfake Expert No Longer Trusts His Own Eyes

https://www.nytimes.com/2026/06/14/us/ai-deepfake-hany-farid.html
2•jonbaer•8m ago•0 comments

Where do migrants live, and where were they born?

https://ourworldindata.org/where-do-migrants-live-and-where-were-they-born
1•surprisetalk•10m ago•0 comments

The Art of Noises

https://www.arthistoryproject.com/artists/luigi-russolo/the-art-of-noises/
1•jruohonen•11m ago•0 comments

Show HN: AI vs. AI – code and reviews only count if they survive an attack

https://github.com/lolu1032/pantheon-skills
1•lolu1032•11m ago•0 comments

How We Run Firecracker VMs Inside EC2 and Start Browsers in <1s

https://browser-use.com/posts/firecracker-browser-infra
1•gregpr07•11m ago•1 comments

Viral "dopamine sites" let users shop without buying anything

https://www.dexerto.com/entertainment/dopamine-sites-that-mimic-online-purchase-experience-for-sh...
2•randycupertino•11m ago•1 comments

Ask HN: What are some good/fast coding models for Apple Silicon?

1•LoganDark•11m ago•1 comments

Ask HN: Is our data warehouse setup normal or over-complicated?

2•ealready_value•13m ago•0 comments

Wait, How Do You Pronounce Turkey? [video]

https://www.youtube.com/watch?v=WzohU9JYWOg
2•dataflow•13m ago•0 comments

Show HN: Infer0 – do AI apps need subscriptions?

https://infer0.com/
3•sumolessons•13m ago•0 comments

Show HN: Absolute best option for networkmanager in Rust

https://github.com/networkmanager-rs/nmrs
2•cachebag•16m ago•0 comments

SpaceX Acquires Cursor for $60B: What It Means for Software Security

https://www.pentesty.co/blog/spacex-acquires-cursor-60-billion-software-security
4•johnzoro107•16m ago•0 comments

The Daemon in the Middle

https://blog.tacoda.dev/the-daemon-in-the-middle-a7a2ae4503fb
2•tacoda•16m ago•0 comments

Bundt Cakes

https://tck.mn/food/bundt/
3•FinnLobsien•17m ago•0 comments

Catastrophic DoorDash Outage

https://www.doordashstatus.com
3•40four•18m ago•3 comments

KeyCon 2026 Recap

https://cassidoo.co/post/keycon-2026/
2•mooreds•19m ago•0 comments

For the last 2 years, 95% of my conversations have been with LLMs

https://www.youtube.com/watch?v=gf0-L5om_HM
2•emzra•19m ago•0 comments

Google Chrome's Next Update Will Mark the End of Popular Ad Blockers

https://tech.slashdot.org/story/26/06/15/205219/google-chromes-next-update-will-mark-the-end-of-p...
19•arnejenssen•21m ago•4 comments

Reading Ulysses: Splendid literature that can suck the life out of you

https://www.irishtimes.com/culture/books/2025/06/11/reading-ulysses-splendid-literature-that-can-...
3•pretext•21m ago•0 comments

AI is good at web design now

https://repaint.com/blog/ai-is-good-at-web-design-now
2•benshumaker•21m ago•0 comments

Google Chrome is closing the loopholes that let old ad blockers keep working

https://www.theverge.com/tech/950005/google-chrome-removing-ad-blocker-loopholes
2•taubek•22m ago•0 comments