frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Tapeworm hijacks worker ants, giving them queen-like metabolism and longer lives

https://phys.org/news/2026-07-tapeworm-hijacks-worker-ants-queen.html
1•wglb•24s ago•0 comments

Why I Am Not Going to Buy a Computer

https://karlvmuller.com/posts/why-i-am-not-going-to-buy-a-computer/
1•KarlVM12•1m ago•0 comments

Is Passwork safe for your business?

https://proton.me/business/blog/is-passwork-safe
1•Erenay09•1m ago•0 comments

What Foreign Architects Get Wrong in the Global South

https://commonedge.org/what-foreign-architects-get-wrong-in-the-global-south/
1•surprisetalk•3m ago•0 comments

AI tool reveals climate shifts may have fueled bursts of bird evolution

https://news.umich.edu/ai-tool-reveals-climate-shifts-may-have-fueled-bursts-of-bird-evolution/
1•gmays•3m ago•0 comments

I Am Buiding BorgIOS

https://github.com/bitmonky/BorgIOS
1•BorgIOS•4m ago•0 comments

Is software enshittified?

https://www.natemeyvis.com/is-software-enshittified/
1•Brajeshwar•4m ago•0 comments

Show HN: Bento - An entire PowerPoint in one HTML file (edit+view+data+collab)

https://bento.page/slides/
1•starfallg•4m ago•0 comments

Show HN: PDF tools that run in the browser, no upload

https://pdfcdf.com
1•sofiurrr•6m ago•0 comments

IMDB now automatically creating user accounts when you are signed into Amazon

1•terminalbraid•6m ago•0 comments

Hilo Raises $19M for Blood Pressure Wearables

https://insider.fitt.co/hilo-raises-19m-for-blood-pressure-wearables/
1•brandonb•7m ago•0 comments

UK Pols Want More Speech Regulation After Ann Widdecombe Murder – She Opposed

https://jonathanturley.org/2026/07/22/uk-politicians-call-for-more-speech-regulation-after-the-mu...
1•anonymousiam•7m ago•1 comments

Show HN: Made a App to Turn Any Podcast into a Website

https://audioenhancer.com/
1•wbemaker•7m ago•0 comments

How to choose a Linux kernel subsystem to work on (as a beginner)

https://cjd8.github.io/kernel/kbeginner/2026/07/22/how-to-start-kernel-work.html
1•cjd8•8m ago•1 comments

A theory of the origins of cognitive inequality

https://davidbessis.substack.com/p/attention-is-all-we-have
1•igonvalue•8m ago•0 comments

AFAWA's support for women entrepreneurs has promoted business expansion in Kenya

https://www.afdb.org/en/success-stories/how-afawas-support-women-entrepreneurs-has-promoted-busin...
1•thunderbong•8m ago•0 comments

Neo Radar: A browser-based orbital mechanics engine with 41k real asteroids

https://neoradar.space
1•daviazpen•8m ago•0 comments

Show HN: BBRv3 for gVisor's netstack, visualized in the browser using WASM

https://ccsim.apoxy.dev
1•dilyevsky•9m ago•0 comments

Forensic Statistics in Python

https://www.johndcook.com/blog/2026/07/21/forensic-accounting-in-python/
1•ibobev•9m ago•0 comments

Building a Live TV Player from Scratch

https://blog.jaysmito.dev/blog/03-live-tv-inside-vulkan/
1•ibobev•9m ago•0 comments

Generating Random Numbers?

https://blog.jaysmito.dev/blog/01-generating-random-numbers/
2•ibobev•10m ago•1 comments

Where Are All the Solar-Powered Cars?

https://spectrum.ieee.org/solar-powered-cars
1•rbanffy•10m ago•0 comments

Why Artists Hate Finishing Their Own Work

https://comuniq.xyz/post?t=1421
2•01-_-•10m ago•0 comments

U.S. Majors with Lowest Pay and Highest Unemployment 5 Years Post Graduation

https://insurancedimes.com/2026/07/21/13-us-majors-with-the-lowest-pay-and-highest-unemployment-f...
1•crookedroad44•10m ago•0 comments

When I have fears that I may cease to code

https://gist.github.com/sh1nj1/273a889eb3c23a48b55c7de69233c15b
1•chk0ndanger•10m ago•0 comments

Generate LoRA Adapters from Skill.md Files for Long Agentic Tasks

https://www.terradev.cloud/
1•Facingsouth•10m ago•0 comments

Srenix – self-healing Kubernetes in a 30MB binary (Apache-2.0)

https://github.com/SRENIX-AI/agentic-sre
1•srenix-ai•10m ago•0 comments

How to Turn a 2D Concept into a Colorful and Lively 3D Environment

https://80.lv/articles/how-to-turn-a-2d-concept-into-a-colorful-and-lively-3d-environment
1•01-_-•11m ago•0 comments

Pixar Bears Brunt of Disney Layoffs as Company Axes Several Hundred Staffers

https://variety.com/2026/film/news/pixar-layoffs-disney-studios-several-hundred-employees-1236817...
1•ksec•11m ago•0 comments

OpenAI Presence

https://openai.com/index/introducing-openai-presence/
5•getnoenemy•11m ago•0 comments
Open in hackernews

Passkeys were invented by engineers with zero understanding of consumer brain

https://twitter.com/nikitabier/status/2079787406300266743
66•ksec•59m ago

Comments

voidmain0001•36m ago
It just so happened that Microsoft sent an email today to our M365 tenant administrators that SMS and voice for 2FA is being removed 1-Feb-2027 and that automatic enrollment to passkeys starts 1-Sep-2026. Bring on the passkey overlords. Although, LLMs say that passkeys are superior to passwords since it includes a public/private key setup with the private key saved to a device that requires a PIN or biometric to access the private key.
SirFatty•29m ago
That's if you're using Authenticator.
bflesch•32m ago
My tinfoil hat take is that there's significant interest to keep everything digital, always-online and connected to the major providers, so it can easily be snooped by five eyes using their omnipresent backdoors.

Passkey biometrics also allow you to confirm certain person is holding the device right in this very moment, and not receiving a TOTP via walkie-talkie. Especially important for kinetic sanctions.

If you check out their Terramare group of companies those guys are still using typewriters. Unless you're US/UK millionaire I recommend to stay as analog as possible with physical password book and TOTP/yubikey.

Same with the push for "post-quantum crypto" and elliptic curves. I feel my systems get significantly more attention when using 8k RSA than any of its modern replacements. While I love wireguard the transition to ED25519 felt way too smooth..

forsalebypwner•21m ago
the fact that some nebulous "group of companies" still uses typewriters does not mean that all modern cryptography is flawed
bflesch•16m ago
Diversity is resilience; no need to standardize on curves or "post-quantum" IBM bullshit if other approaches still work perfectly fine.

And if the pros are using typewriters in 2026 it's not a signal for me to put even more eggs into the US-megacorp dominated basket who treat me like an NPC who can be droned at will.

coldpie•32m ago
Passkeys are a vector for locking your logins to Big Tech ecosystems. They support device attestation, which means the service you are logging in to can require you to only use certain Passkey clients such as those provided by Google, Apple or Microsoft. The Passkey spec authors also maintain a list of "naughty clients"[1], which are clients that allow the user to manage their own data how they want. Services could choose to block those clients for "security reasons," justifying the decision to force you to use one of the Big Tech providers.

Until device attestation is removed or strongly curtailed in the spec, I suggest you do not create any Passkeys. Which sucks, because it's otherwise a pretty cool tech.

[1] https://passkeys.dev/docs/reference/known-issues/

More sources here: https://www.smokingonabike.com/2025/01/04/passkey-marketing-...

datakan•27m ago
Passkeys are just SSH keys in how they work. We've been doing this since the 90's. The only people that use SSH keys are the Linux savvy users and those who are forced to via an enterprise solution for vaulting.

The average person doesn't know anything about this stuff nor do they care. I also have yet to see a Passkey solution that didn't also have a password on it and a nice little box letting people choose to use the password instead of the passkey. They just added a new layer on top of all the old ones and created confusion. Now people use password and passkey interchangably in conversations and no one knows what they are talking about.

account42•24m ago
SMS 2FA was also optional everywhere until it wasn't.
cpburns2009•15m ago
I can find my ssh keys in `~/.ssh`. No such place exists for passkeys.
microflash•4m ago
It depends on the app you’re using to save passkeys. Use Keepass and it save the passkeys into kdbx file (similar to SSH keys).
juancn•9m ago
I would feel a lot better using SSH keys rather than passkeys. At least those are understandable.
IceHegel•26m ago
I think there are probably sinister motives behind some of the push to pass keys, but you'd think that if that were true, they would make it really quite easy to add one and to use.

That is not the case. The entire setup/enrollment/add a passkey to your account processing is DMV inspired.

postalrat•20m ago
Its a lot easier to track email and phone numbers used across multiple sites than it is passkey used on multiple sites.
gortok•24m ago
I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand:

I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use LastPass. If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? Is there a way to ensure that passkey can be used on other devices? Can I add another passkey on another device? How many passkeys can I set up for a particular site/app? I have at least 6 different combination of browser/devices in use.

I don’t want to use Passkeys because I don’t the answers to those questions, and I don’t know whether each website/app that has set up Passkeys has decided the answers to those questions in the same way as the others. For now, I’m going to stick with LastPass and use Passwords; because no matter whether I lose my device or not or whether I’m on my own devices or not, I can be sure I’ll be able to get into a site/app.

cpburns2009•17m ago
This is the main reason I've avoided passkeys. I have these exact questions and there's no a clear explanation given for these. I don't want to lose access to important accounts.
wadim•17m ago
I'm using bitwarden, but it's possible to use passkeys from multiple devices and if it's not available for whatever reason, you can just login with username/password/token/biological probe/whatever you used before. As an example: GitLab gives you both options right from the start, so you can use whatever you fancy in that particular moment.
FireBeyond•14m ago
exabrial•23m ago
With physical U2F key, I could explain to my 78 year-old-parents "this is a physical key needed to access your account. Think of it like the front door key to your house. Don't lose it or lend it to anyone. We should have a couple of backup keys too." And they got completely understood and added it to all of their accounts. This was not hard. People assumed consumers were too stupid to do this without even giving them a chance.
JohnFen•18m ago
> Don't lose it or lend it to anyone. We should have a couple of backup keys too.

Honestly, this is one of the two things that make me hate passkeys. The key management is a high-friction pain in the ass.

programmertote•13m ago
Like some folks already commented here, even as someone who has been working in tech for 20+ years, I find Passkey confusing. I understand the key aspect in computer science term, but I don't know how to use it across devices. Another big worry is that if I tie that to a physical key, then I might lose it (because it's physical) and never get it back.
varispeed•12m ago
I find it difficult to explain how to use password manager to non-IT person. Whatever I say, they say it is not secure. No amount of explanation will change their mind. They prefer to keep their passwords in their physical note book hidden in the safe (yes, they open the safe etc each time they need to log in somewhere when they get logged out).

As someone with ADHD a passkey is something I can lose easily and I don't want my accounts to be tied to any specific device. What if I have to upgrade my laptop tomorrow because one I use got bricked? Sounds like an absolute nightmare.

Password on the other hand I can remember for dozens of services, each very long.

ElijahLynn•8m ago
I only use pass keys by storing them in 1password. Then I don't have to worry about the whole "lose/broke/replace a device" thing, which is inevitable. Then just be really good about keeping your backup codes etc with 1pass solid.
mullingitover•7m ago
You’d think a head of product at a tech company would embrace a “it’s literally impossible to have your password stolen if you use this” technology.
rsyring•5m ago
FWIW: I find passkeys to be a very simple and easy to use concept.

Simple: it's like a password that I don't have to type in

Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices.

Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level. But before that, I was simply sharing passwords through 1Password in the exact same way. So, I don't think my security posture has changed any.

What has changed is the UX and IMO for the better. Now I don't have to generate/fill/copy-paste text strings. 1Password knows what site I'm on and usually responds automatically when I'm in a passkey context.

Honestly, it's mostly a "just works" system and I like it a lot better than passwords.

YMMV, of course.

Did [someone from the Working Group] ever back down from their implied threat to blacklist Bitwarden for allowing for the sharing/export of passkeys?

That really rubbed me the wrong way, and smacked very heavily of "the big players (MSFT, AAPL, GOOG) can do this - you can't".

cpburns2009•11m ago
I know KeePassXC faced the same threat. I don't know whatever became of it.
mingus88•13m ago
It’s really not that hard.

Most of your devices are in the Apple ecosystem and when you are prompted to create a passphrase it will ask you to put it in your iCloud Keychain. Boom, now it is available across all of those

This is how it will work for most people who don’t care about security and just casually use their devices. My boomer mom does this. It’s better than the notebook full of handwritten passwords she was using.

You have chosen lastpass and a multi-ecosystem environment with windows and multiple browsers on each. You have chosen complexity and this is not a limitation of passsphrases as they have been designed for a more common use case.

I use Linux and apple. I have chosen protonpass for my vault. I just tell my OS to save the passkey there and everything works pretty well. If not, my password is right there as fallback. It’s really not that hard.

juancn•10m ago
What if I lose all my apple devices? House break-in and they steal my mac and my phone?

You're basically fucked even if you buy a new one because you need one of the other two to log in.

gretch•7m ago
No technology in the world can protect you against every threat model and unlikely scenario.

What if the robber hits you in the head and you get brain damage and forget your password?

coldpie•10m ago
Proton Pass is on the official Passkey client naughty list[1]. I hope the services you log in to don't choose to ban it because of those big, scary X's.

[1] https://passkeys.dev/docs/reference/known-issues/

corndoge•5m ago
The fact that services can ban passkey providers is a major red flag in the protocol and the real issue that nobody talks about
juancn•12m ago
Same here, also what if I lose the device?

I can safely write down a password on a piece of paper and keep it somewhere phyisically safe.

Passkeys and 2FA are a usability nightmare if you need to recover, or all the security vanishes if you put usable recovery mechanisms for the passkey or the second factor.

varispeed•11m ago
Sounds like something security services would love people to use. Instead of using wrench to extract the password - and distressed person may lose memory, they can just locate the passkey.
msandford•4m ago
Nobody is safe from a nation-state "attack" they'll just go threaten your providers to give up your data. Passwords written on paper are probably safer than a centralized password manager for almost every circumstance other than a government coming after you.
darknavi•11m ago
Why not use passkeys in LastPass? Then the passkey travels with you to your devices/apps.
microflash•9m ago
You can store your passkeys in Bitwarden or Keepass vault. Then you can use them through Bitwarden or Keepass apps on any other device. Been using passkeys like this for several years, and it works pretty seamlessly. With Keepass vault, I even have an offline copy as backup.
owaislone•7m ago
Answer to almost all of your questions is that it entirely depends on the service what kind of auth implementation they offer. I personally have completely adopted passkeys and use them with every service that allows it.

I use ProtonPass and have made it the default password store on every device and browser. This way all passkeys get stored in proton and I can login from any other personal device with proton setup.

summermusic•5m ago
> ...it entirely depends on the service what kind of auth implementation they offer.

I think that's exactly the problem. These are all answerable questions, but getting those answers is confusing for most people.

bflesch•6m ago
Passkeys basically MITM the 2FA process so that they can track and deplatform you with a single click across all your accounts.

The biometric verification also allows to confirm that a certain person is holding the device, and they can easily be matched to existing passport/travel databases.

Great system if the good guys have it, a bit problematic if it's abused by nepo kids to hide their crimes.

notatoad•4m ago
these questions all have easy answers that could be quite easily discovered by simply trying to use passkeys, instead of trying to find reasons not to use them.