frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Vouch

https://github.com/mitchellh/vouch
464•chwtutha•19h ago•203 comments

Shifts in U.S. Social Media Use, 2020–2024: Decline, Fragmentation, Polarization

https://arxiv.org/abs/2510.25417
20•vinnyglennon•34m ago•0 comments

Apple XNU: Clutch Scheduler

https://github.com/apple-oss-distributions/xnu/blob/main/doc/scheduler/sched_clutch_edge.md
38•tosh•1h ago•3 comments

Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/
79•nullcathedral•4h ago•18 comments

More Mac malware from Google search

https://eclecticlight.co/2026/01/30/more-malware-from-google-search/
13•kristianp•1h ago•2 comments

A GTA modder has got the 1997 original working on modern PCs and Steam Deck

https://gtaforums.com/topic/986492-grand-theft-auto-ready2play-full-game-windows-version/
76•HelloUsername•1h ago•25 comments

The Little Bool of Doom (2025)

https://blog.svgames.pl/article/the-little-bool-of-doom
63•pocksuppet•4h ago•21 comments

International Image Interoperability Framework

https://iiif.io/
18•rishikeshs•5d ago•3 comments

Show HN: I created a Mars colony RPG based on Kim Stanley Robinson's Mars books

https://underhillgame.com/
100•ariaalam•5h ago•44 comments

Everything – Locate files and folders by name instantly

https://www.voidtools.com/
58•idw•1h ago•27 comments

Formally Verifying PBS Kids with Lean4

https://www.shadaj.me/writing/cyberchase-lean
61•shadaj•6d ago•4 comments

Running Your Own As: BGP on FreeBSD with FRR, GRE Tunnels, and Policy Routing

https://blog.hofstede.it/running-your-own-as-bgp-on-freebsd-with-frr-gre-tunnels-and-policy-routing/
116•todsacerdoti•8h ago•47 comments

GitHub Agentic Workflows

https://github.github.io/gh-aw/
179•mooreds•8h ago•95 comments

Exploiting signed bootloaders to circumvent UEFI Secure Boot

https://habr.com/en/articles/446238/
79•todsacerdoti•7h ago•44 comments

I put a real-time 3D shader on the Game Boy Color

https://blog.otterstack.com/posts/202512-gbshader/
213•adunk•5h ago•25 comments

RFC 3092 – Etymology of "Foo" (2001)

https://datatracker.ietf.org/doc/html/rfc3092
108•ipnon•7h ago•24 comments

Dave Farber has died

https://lists.nanog.org/archives/list/nanog@lists.nanog.org/thread/TSNPJVFH4DKLINIKSMRIIVNHDG5XKJCM/
192•vitplister•10h ago•27 comments

Omega-3 is inversely related to risk of early-onset dementia

https://pubmed.ncbi.nlm.nih.gov/41506004/
196•brandonb•5h ago•122 comments

Bun v1.3.9

https://bun.com/blog/bun-v1.3.9
118•tosh•4h ago•28 comments

SpiceDB Query Planner

https://authzed.com/blog/introducing-spicedb-query-planner
10•mparnisari•5d ago•0 comments

Curating a Show on My Ineffable Mother, Ursula K. Le Guin

https://hyperallergic.com/curating-a-show-on-my-ineffable-mother-ursula-k-le-guin/
143•bryanrasmussen•12h ago•47 comments

Credentials for Linux: Bringing Passkeys to the Linux Desktop

https://alfioemanuele.io/talks/2026/02/01/fosdem-2026-credentials-for-linux.html
33•alfie42•5h ago•20 comments

Billing can be bypassed using a combo of subagents with an agent definition

https://github.com/microsoft/vscode/issues/292452
168•napolux•5h ago•87 comments

Show HN: It took 4 years to sell my startup. I wrote a book about it

https://derekyan.com/ma-book/
173•zhyan7109•4d ago•45 comments

OpenClaw is changing my life

https://reorx.com/blog/openclaw-is-changing-my-life/
185•novoreorx•16h ago•310 comments

Kolakoski Sequence

https://en.wikipedia.org/wiki/Kolakoski_sequence
60•surprisetalk•6d ago•12 comments

The first sodium-ion battery EV is a winter range monster

https://insideevs.com/news/786509/catl-changan-worlds-first-sodium-ion-battery-ev/
105•andrewjneumann•5h ago•113 comments

A Community-Curated Nancy Drew Collection

https://blog.openlibrary.org/2026/01/30/a-community-curated-nancy-drew-collection/
13•sohkamyung•5d ago•3 comments

Let's compile Quake like it's 1997

https://fabiensanglard.net/compile_like_1997/index.html
107•birdculture•5h ago•38 comments

Why E cores make Apple silicon fast

https://eclecticlight.co/2026/02/08/last-week-on-my-mac-why-e-cores-make-apple-silicon-fast/
213•ingve•10h ago•209 comments
Open in hackernews

Credentials for Linux: Bringing Passkeys to the Linux Desktop

https://alfioemanuele.io/talks/2026/02/01/fosdem-2026-credentials-for-linux.html
32•alfie42•5h ago

Comments

digiown•1h ago
Passkey/webauthn is a cool tech, and I'd really like to use it everywhere, but I find the anti-user attitudes of the spec authors concerning. The spec contains provisions about "user verification" (the software must force user interaction) and not allowing the user to access the plaintext keys. It appears that the spec authors do not consider the keys to be owned by the user at all.

KeepassXC implements passkey support, but they do not implement these anti-user features. As a result, they are being threatened with being banned via attestation:

https://github.com/keepassxreboot/keepassxc/issues/10406

https://github.com/keepassxreboot/keepassxc/issues/10407

Screw these "You'll own nothing and be happy" people. I'll own all my keys no matter what. The software I run on my device should never betray me to signal things like "this passkey is allowed to be backed up!".

cadamsdotcom•1h ago
Agreed, unfortunately.

Passwords are easy to understand, transparent and portable, and when used with good hygiene (always using password manager and generating unique & strong passwords for everything) there isn’t yet a strong case for anything else.

doubled112•6m ago
I’m not happy with everything about passkeys either. I am fine with them as an additional method, but I would never use them as the only method.

That said, I had a much easier time getting my kids onboard with a FIDO2 security key than I would have a password manager.

Enter your email and touch this is easy to understand.

giancarlostoro•1h ago
How do you even ban something like KeypassXC given that it is open source and any end user could basically edit KeypassXC and bypass a ban?

Edit: Reading one of those issues it sounds like they want the keys stored in an encrypted way, is that too much to ask for? I dont care about viewing it but it shouldnt be stored in a plain easy to open JSON.

digiown•1h ago
That's the thing, they can't yet.

They are proposing an attestation scheme. I'm not sure the details are out yet, but the authenticator would presumably use one of the hardware security mechanisms (like a TPM bound key) to "certify" its own authenticity along with the challenge.

This will effectively ban all open-source implementations, and end user freedom if widely adopted. Fortunately for us it seems like Apple isn't cooperating here for now, and without Apple signing on, it wouldn't get anywhere.

digiown•1h ago
It's an export format. The storage is always encrypted with the database key. And you can view the key directly anyway just like you can view passwords, and copy it from there.
politelemon•1h ago
> ask for

That's the key difference. If it mattered, they would make it part of the spec, not threaten a ban. That's even more concerning, there is a central group of people who get to decide who can and cannot use Passkeys.

Dedime•48m ago
Well, it's stored in an encrypted way - in the encrypted password database. Much like a password, everyone already knows not to share a passkey. But also like a password, as the owner, sometimes I want to look at it!
frizlab•40m ago
Genuine question: why?
TomasEkeli•24m ago
it's mine.
signal11•1h ago
Shafting open source projects that implement your spec is not okay, and is terrible optics.

Tech journalists should ask the FIDO Alliance if they’re just Google+Apple+Microsoft in a trenchcoat. Definitely not very open!

digiown•1h ago
I do get that there are use cases for actual hardware bound keys for enterprise settings. But having non-exportable credentials (effectively non-ownable) is not acceptable in a consumer setting. This is a thinly veiled attempt at strengthening platform lock-in.

Look, the spec says you can't export the keys to a file! Too bad, go re-register your 120 websites if you want to stop using iCloud/Google!

Groxx•31m ago
Particularly because "you must use only an approved passkey manager" is fairly easily solved by MDM, which is already widespread.

It's DRM, and it will go down exactly the same anti-user and anti-competitive route as every other DRM. Fight it with fervor.

politelemon•1h ago
> It appears that the spec authors do not consider the keys to be owned by the user at all.

This was my impression, and it explains why the original announcement involved companies that would benefit the most from keeping their users on a leash.

AndrewDucker•53m ago
They don't consider the key to belong to the user. The key is a token generated by the site to allow it to identify a user. In order for them to do perfectly so they do not want users to be able to tamper with them, leak them, or do anything which might violate their assumptions about the key.
notepad0x90•1h ago
I just wish more people would protest this instead of things like secure boot.

Password managers and/or operating systems can manage private keys just fine. websites shouldn't be concerned with how the keys are managed, or be able to make demands on how users store credentials, or know device details for users.

One thing I dislike even with systems like FIDO2 is that the websites/apps can block list your FIDO key's vendors. Similar trends suck. Passkeys are just one iteration in a long line of systems designed with corporate interests in mind.

The system validating the authentication needs only to verify that the credentials are correct. If users want to use TPMs, HSMs,etc.. or none at all, that's up to them. And no information, other than what is strictly required to verify the credential should be transmitted over the network. a signature of challenge data from the app should be sufficient. the user's public key shouldn't be signed at all by hardware, a trusted 3rd party,etc.. the registration process should take care of establishing public key trust to the authenticator/app. The whole thing feels insidious.

digiown•1h ago
Corporate interests HATE general purpose computing, and the freedom to run what you want. With that freedom, you can hurt their interests by blocking ads, stripping out spyware, or avoiding giving up your privacy, and they can't let you have that.

It's a death by thousand cuts that's finally starting to come together:

- Remote attestation like Play "integrity"

- Hardware backed DRM like Widevine

- No full access to filesystem on Android, and no access to filesystem at all on iOS

- No ability to run your own programs at all on iOS without Apple's permission.

- "Secure" boot on Android and iOS that do not allow running your own software

Ever wondered why Windows 11 have a TPM requirement? No, it's not just planned obsolescence.

If they get their way, user-owned computers running free software will never be usable again, and we'll lose the final escape hatch slowing down the enshittification of computers. The only hope we have is that they turn up the temperature a little too quickly that normies would catch on before it gets far enough.

jmclnx•1h ago
I fully agree, seems Linux is heading directly towards being a Windows Clone. So far all the windows crap can be easily avoided, but once these things are forced on me, it is bye bye Linux.

Already I use BSD on an older laptop probably 40% of the time. Linux on my main system is there due to a hardware device issue BSD still have a minor problem with it. But for me right now, Linux seems to be heading in a wrong direction.

digiown•56m ago
KeepassXC implements passkeys in a respectful way. I don't see how this is "Windows crap". If they want to force attestation on passkey implementations, whether or not Linux supports it will not matter.
hexo•36m ago
No thanks, it stinks.