frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•7mo ago

Comments

kemotep•7mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Deleting Substack account after Australia age laws

1•freefrog334433•3m ago•0 comments

Agentic coding tools should give more control over message queueing

https://solmaz.io/agentic-coding-tools-message-queueing
1•hosolmaz•4m ago•0 comments

Tumbleweeds inspire this rolling, resilient robot

https://www.popsci.com/technology/tumbleweed-robot-hermes/
1•Brajeshwar•4m ago•0 comments

Beyond Disagree and Commit

https://duncan.dev/post/beyond-disagree-and-commit
1•gpi•4m ago•0 comments

I Migrated an Oracle Schema to YugabyteDB

https://hexacluster.ai/blog/migrating-schema-from-oracle-to-yugabytedb-using-hexarocket
2•jones_david•5m ago•1 comments

Mini Brains Grown from Stem Cells Developed Light-Sensitive, Eye-Like Features

https://www.smithsonianmag.com/smart-news/mini-brains-grown-stem-cells-developed-eyes-can-sense-l...
2•thunderbong•8m ago•0 comments

Europe must be ready when the AI bubble bursts

https://www.ft.com/content/0308f405-19ba-4aa8-9df1-40032e5ddc4e
1•Brajeshwar•10m ago•1 comments

Guarding My Git Forge Against AI Scrapers

https://vulpinecitrus.info/blog/guarding-git-forge-ai-scrapers/
1•todsacerdoti•20m ago•0 comments

Let's Embed a Go Program into the Linux Kernel

https://sigma-star.at/blog/2023/07/embedded-go-prog/
1•birdculture•20m ago•0 comments

People power: How LLMs invert tech diffusion

https://karpathy.bearblog.dev/power-to-the-people/
2•keepamovin•20m ago•0 comments

System76 Launches Pop _OS 24.04 LTS with Cosmic Desktop

https://www.phoronix.com/news/System76-Ships-Pop-OS-24.04
2•abdullah2993•24m ago•0 comments

Show HN: Toqen – privacy-first authentication flow with QR and TOTP

https://www.toqen.app/
1•antonmb•25m ago•0 comments

OpenAI latest model ChatGPT 5.2 fails a simple logic problem

1•lihaciudaniel2•26m ago•2 comments

Baseline: Operation-Based Evolution and Versioning of Data

https://arxiv.org/abs/2512.09762
2•mrauha•34m ago•0 comments

Smartphone Without a Battery (2022)

https://yaky.dev/2022-09-06-smartphone-without-battery/
3•MYEUHD•34m ago•0 comments

The tiniest yet real telescope I've built

https://lucassifoni.info/blog/miniscope-tiny-telescope/
23•chantepierre•35m ago•4 comments

LaunchSoon: Convert social followers to email subscribers before you launch

https://launchsoon.io/
1•dzungfz•37m ago•0 comments

Revisiting Quantum Supremacy: Simulating Sycamore-Class Circuits Using HPC

https://arxiv.org/abs/2512.07311
1•ulam2•42m ago•0 comments

AI Accountants – FINA AI

https://fina.team/
1•elevateyou•42m ago•1 comments

Show HN: Stimm – Low-Latency Voice Agent Platform (Python/WebRTC)

https://github.com/stimm-ai/stimm
2•stimm•46m ago•1 comments

Swift Configuration 1.0 Released

https://swift.org/blog/swift-configuration-1.0-released/
3•frizlab•47m ago•0 comments

Architecture Decision: Why We Moved from Web to Desktop for Reddit Automation

https://www.wappkit.com/blog/why-desktop-architecture
1•asphero•49m ago•0 comments

Disco is Google's new generative AI web app experience

https://blog.google/technology/google-labs/gentabs-gemini-3/
1•ChrisArchitect•51m ago•1 comments

Crumbling New York Parking Garages Get a New Life

https://www.nytimes.com/2025/12/10/realestate/parking-garage-apartment-housing-conversion.html
3•JumpCrisscross•51m ago•0 comments

Ntoh*/hton* is a bad API

https://purplesyringa.moe/blog/ntoh-hton-is-a-bad-api/
1•PaulHoule•51m ago•0 comments

AI Could Be the Railroad of the 21st Century. Brace Yourself

https://www.derekthompson.org/p/artificial-intelligence-could-be
3•DeathArrow•54m ago•1 comments

MCP Joins the Linux Foundation

https://github.blog/open-source/maintainers/mcp-joins-the-linux-foundation-what-this-means-for-de...
4•senorqa•56m ago•3 comments

Zip Files as (Simple) Key-Value Stores

https://benjamincongdon.me/blog/2025/12/11/Zip-Files-as-Simple-Key-Value-Stores/
2•ingve•1h ago•0 comments

Ford's Car of the Future, Hatched in a Skunk Works Near Los Angeles

https://www.nytimes.com/2025/12/11/business/ford-electric-vehicles-china.html
1•ianrahman•1h ago•0 comments

Anthropic Donated to Linux Agenic AI Foundation(AAIF)

https://aaif.io/
1•zkitty•1h ago•2 comments