frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•10mo ago

Comments

kemotep•10mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: Nemp Memory – local project memory that survives tool switching

https://www.nemp.dev/
1•sukinai•12s ago•0 comments

The Hater's Guide to Oracle

https://www.wheresyoured.at/haters-guide-oracle/
1•NoGravitas•1m ago•0 comments

MongoDB Stock Falls 27% Even as Earnings Beat Estimates

https://www.barrons.com/articles/mongodb-earnings-stock-price-fc2ad40b
1•alecco•1m ago•0 comments

Show HN: FakeScan – Free AI fake review detector (Fakespot alternative)

https://fakescan.site
1•crawde•1m ago•0 comments

Show HN: PingMeBud – A macOS app that listens to meetings so you don't have to

https://www.pingmebud.com/
1•spaceman3•2m ago•0 comments

Show HN: ScrapAI – We scrape 500 sites. AI runs once per site, not per page

https://github.com/discourselab/scrapai-cli
1•iranu•2m ago•1 comments

The SaaS-pocalypse is (somewhat) overblown

https://12gramsofcarbon.com/p/tech-things-saas-is-dead-long-live
1•theahura•3m ago•0 comments

Show HN: I built an AI data analyst that never sees your data

https://www.queryveil.com/blog/i-built-an-ai-data-analyst-that-never-sees-your-data
1•david-rodriguez•4m ago•1 comments

Show HN: GovMatch – Daily government contract alerts matched to your business

https://www.govmatch.live/
1•realdanigil•4m ago•0 comments

France will allow temporary deployment of nuclear-armed jets to European allies

https://apnews.com/article/france-nuclear-weapons-macron-deterrence-ccbcfb03ef4a1e3efe287fb744adb148
2•geox•4m ago•0 comments

Better News

https://doc.searls.com/2026/03/03/better-news/
1•speckx•5m ago•0 comments

Bunny.net Shared Storage Zones

https://dbushell.com/2026/03/04/bunny-shared-storage-zones/
1•speckx•6m ago•0 comments

Pre-Order: Asimov DIY Kit – Build a Humanoid Robot

https://asimov.inc/diy-kit
1•bilsbie•6m ago•0 comments

EU MEPs let Chat Control fail

https://www.heise.de/en/news/Setback-for-the-Commission-EU-MEPs-let-chat-control-fail-11197237.html
1•carschno•8m ago•0 comments

Show HN: We built a zero-webhook Merchant of Record for SaaS

https://www.kelviq.com/
1•sachinneravath•9m ago•0 comments

Claude Code Permission Policy

https://github.com/defrex/claude-code-permission-policy
1•defrex•9m ago•0 comments

AutomaDocs – AI-powered documentation that stays in sync with your code

https://automadocs.com
2•purplegumdropz1•10m ago•0 comments

My first science video in 3 years (Pysics Girl)

https://www.youtube.com/watch?v=B3m3AMRlYfc
2•pcdavid•10m ago•0 comments

Gregory Gerganov and llama.cpp team joining HF

https://huggingface.co/blog/ggml-joins-hf
1•spwa4•11m ago•0 comments

Show HN: Run any Google Chrome version(+116) in Docker for web automation

https://github.com/blitzbrowser/blitzbrowser
1•sam_march•12m ago•0 comments

Space Jellyfish Predictor

https://jellyfish.johnkrausphotos.com/homepage
1•LorenDB•12m ago•0 comments

Florida public universities to pause hiring new H-1B workers

https://www.wusf.org/education/2026-03-03/hiring-h1b-workers-florida-public-universities-pause-en...
1•rawgabbit•13m ago•0 comments

Zero Public Ports: How I Secured a B2B API Against 10K Scraper Requests

https://blog.tripvento.com/zero-public-ports-how-i-secured-my-b2b-api
1•iistrate3•14m ago•0 comments

Show HN: Open-source digital signage ecosystem to escape vendor lock-in

1•sagiadinos•14m ago•0 comments

Show HN: Vocova – Paste a link, get a transcript in 100 languages

https://vocova.app/
1•jmcraft•17m ago•1 comments

Show HN: BloonsBench – Evaluate agent performance on Bloons Tower Defense 5

https://github.com/cnqso/bloonsbench
1•cnqso•17m ago•1 comments

Lawyers don't need "Legal AI"

https://theredline.versionstory.com/p/why-cant-43b-in-legal-ai-investment
2•jpbryan•18m ago•0 comments

Knowdust – Multi-tool hub for devs and everyday users

https://knowdust.com
1•thenamo•18m ago•1 comments

The gap between vague and specific AI direction is not small

https://thoughts.jock.pl/p/directed-ai-experiments-vibe-business
1•joozio•19m ago•0 comments

We're about to turn night into day. Is that a good idea?

https://www.washingtonpost.com/climate-environment/2026/02/27/satellites-light-pollution-spacex/
1•JeanKage•20m ago•2 comments