frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
16•jchanimal•55m ago

Comments

ted_dunning•31m ago
It is hard to find the content for all of the glitzy ads on this site.
ikidd•28m ago
There's ads?
ted_dunning•15m ago
But when you do, there are glaring holes these people uncovered.
Groxx•26m ago
"You must enable DRM to play some audio or video on this page" pops up in the strangest places...
colemannugent•18m ago
>4. Using the hash of that handshake, the attacker interacts with the victim’s TPM and uses the extracted identity key to sign the handshake hash together with the assertion request

Huh? If you have this level of local privileges you can just read session cookies from the browsers store? I guess stealing all the keys is notable, but you can manipulate any password manager with this level of access right?

What's the threat model here, that synced passkeys should be secure in even in situations involving compromised clients? How?

ted_dunning•13m ago
It's not that simple. The stolen file has no clear text passwords and ideally, these passwords can only be decrypted on the right hardware with user confirmation. Of course, eternal and repeated confirmation requests are an anti pattern all their own, but the cloud attestation service not verifying the hardware sounds like a really glaring omission.
vel0city•11m ago
At least for accounts you want to keep very secure, session cookies are probably very time-limited. Stealing a passkey ensures persistent access in the future.

But I largely agree, if they're able to do this on your system you're already hacked and they can do a ton of very bad things.

Show HN: Misalignments when using AI for hacking

https://blog.vulnetic.ai/ai-misalignment-and-penetration-testing-e812194b67ca?sharedUserId=Vulnet...
1•danieltk76•2m ago•0 comments

A Lightweight Open-Source LLM Benchmark Tool – Compare Any Model on OpenRouter

https://cheikhhseck.medium.com/i-built-a-llm-benchmark-tool-and-tested-it-on-free-models-heres-wh...
1•cheikhdev•6m ago•0 comments

Zigbee vs. Matter over Thread:Understanding IoT Protocol Performance in Practice

https://arxiv.org/abs/2603.04221
2•teleforce•7m ago•0 comments

Bugtraq Is Back

https://lists.securityfocus.com/hyperkitty/list/bugtraq@securityfocus.com/thread/CHKLXLA7SJEWLDFH...
2•bashtoni•11m ago•0 comments

Spotted: Mac Studio with M3 Ultra 256GB RAM and M4 Max with 128GB RAM

https://gpuquicklist.com/blog/m3-ultra-256-and-m4-max-128
1•kristianp•14m ago•0 comments

Flowise Is Shutting Down

https://flowiseai.com/sunset
2•llmgraph•15m ago•1 comments

The Myth of the Food Desert

https://www.newyorker.com/magazine/2026/08/03/food-justice-undone-hanna-garth-book-review
1•delichon•16m ago•0 comments

US has used 'virtually all' of its long-range precision missiles during Iran war

https://www.reuters.com/world/us-has-used-virtually-all-its-long-range-precision-missiles-during-...
2•dataflow•16m ago•0 comments

Feynman's Office; the Last Blackboards [pdf]

https://aip.brightspotcdn.com/PTO.v42.i2.88_1.online.pdf
1•tylerdane•17m ago•1 comments

Eight Myths on Software Engineering and GenAI

https://queue.acm.org/detail.cfm?id=3807963
3•tchalla•26m ago•0 comments

White House excludes open models from framework to test advanced AI capabilities

https://www.axios.com/2026/08/04/trump-ai-framework-open-models
1•petethomas•27m ago•0 comments

Poetry Camera

https://poetry.camera/
1•karakoram•27m ago•0 comments

Lorem Slopsum

https://macro.land/blog/lorem-slopsum/
1•priyadarshy•29m ago•0 comments

Standalone Touch ID Sensor for Mac

https://github.com/zimengxiong/tinytouch
2•ls-a•32m ago•1 comments

Show HN: Find what users want by analyzing app reviews

https://seam.obverselabs.com/
2•OtmaneBenazzou•32m ago•0 comments

Nobody Was Watching: Anthropic, OpenAI, and Open Models

https://substack.norabble.com/p/nobody-was-watching
2•nedruod•35m ago•0 comments

So What's Up with That New CPanel Database Vulnerability?

https://lowendbox.com/blog/so-whats-up-with-that-new-cpanel-database-vulnerability/
1•shaunpud•38m ago•0 comments

Pigeons: SSH Anywhere, Built on Iroh

https://pigeons.computer/
3•AceJohnny2•38m ago•1 comments

2D Vortex Dynamics

https://lee-phillips.org/vortex/
2•leephillips•42m ago•0 comments

US yen intervention signals perfect storm rising in FX and bond markets

https://www.reuters.com/commentary/reuters-open-interest/us-yen-intervention-signals-perfect-stor...
3•mapping365•42m ago•1 comments

Advanced Lawnmower Simulator (1988)

https://en.wikipedia.org/wiki/Advanced_Lawnmower_Simulator
3•yzydserd•42m ago•0 comments

I'm (mostly) picking models on speed now, not intelligence

https://martinalderson.com/posts/speed-vs-intelligence/
2•birdculture•44m ago•0 comments

Appeals Court Agrees with EFF That Building a Web Browser Doesn't Violate CFAA

https://www.eff.org/deeplinks/2026/08/appeals-court-agrees-eff-building-web-browser-doesnt-violat...
8•iamnothere•44m ago•1 comments

Is It Possible to Make Smart Glasses That Aren't Creepy?

https://www.wired.com/story/is-it-possible-to-make-privacy-friendly-smart-glasses/
2•bushwart•45m ago•1 comments

IP and DNS Leaks in WebKit Affecting Proxy Browsers and iCloud Private Relay

https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/
12•lapcat•45m ago•0 comments

TikTok Withheld a Safety Feature from Millions. One Died by Suicide

https://www.bloomberg.com/news/features/2026-08-04/confidential-tiktok-report-shows-algorithm-saf...
2•petethomas•47m ago•0 comments

Crash experiences of highly automated vehicles and human drivers

https://www.iihs.org/api/datastoredocument/bibliography/2374
2•bushwart•49m ago•0 comments

OpenAI pays $3.2M in US probe over hiring foreign workers

https://www.reuters.com/business/openai-pays-32-million-us-probe-over-hiring-foreign-workers-2026...
6•alephnerd•51m ago•0 comments

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
16•jchanimal•55m ago•8 comments

FIPS 140-3 is not a security guarantee, and auditors know it

https://808bits.com/articles/fips-140-3-not-a-security-guarantee/
11•meehow•56m ago•4 comments