frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Russia using Interpol's wanted list to target critics abroad, leak reveals

https://www.bbc.com/news/articles/c20gg729y1yo
1•breve•27s ago•0 comments

An ultra-high-resolution map of (dark) matter

https://www.nature.com/articles/s41550-025-02763-9
1•neom•47s ago•0 comments

Show HN: See how much things cost in terms of your runway

1•yakkomajuri•1m ago•0 comments

Hidden Preference to Auto-Resize Columns in the Finder on macOS

https://forums.realmacsoftware.com/t/auto-resizing-columns-in-finder/52435
1•7777777phil•1m ago•0 comments

Strong vs. swole: the surprising truth about building muscle

https://www.theguardian.com/lifeandstyle/2026/jan/26/strong-v-swole-building-muscle-bodybuilding-...
1•akbarnama•1m ago•0 comments

Sinofuturism (1839 – 2046 AD) [video]

https://vimeo.com/179509486
1•Antibabelic•3m ago•0 comments

The 17% Gap: Quantifying Epistemic Decay in AI-Assisted Survey Papers

https://arxiv.org/abs/2601.17431
1•jruohonen•8m ago•1 comments

Ask HN: How much emphasis to put on unit testing and when?

1•theturtlemoves•10m ago•0 comments

How to Make Your Photos Searchable for the Next 50 Years

https://medium.com/readers-club/the-archivists-secret-how-to-make-your-photos-searchable-for-the-...
1•sony_news•15m ago•0 comments

Logie Baird's Mechanical Televisor

https://paleotronic.com/2018/09/15/gadget-graveyard-bairds-mechanical-television/
1•empressplay•18m ago•0 comments

Y Combinator is no longer investing in Canadian startups

https://thelogic.co/news/exclusive/y-combinator-canada-startups/
3•joelkesler•19m ago•1 comments

Notification Overload (Discussion)

1•fractal618•19m ago•0 comments

Trade Commissioner says 'mother of all deals' will open India market for EU

https://www.euronews.com/my-europe/2026/01/26/exclusive-trade-commissioner-says-mother-of-all-dea...
1•saubeidl•21m ago•0 comments

Limit precise location from cellular networks

https://support.apple.com/en-us/126101
3•tony101•23m ago•0 comments

Kimi open-sourced Kimi Code, a Python-based coding agent

https://twitter.com/Kimi_Moonshot/status/2016034259350520226
1•nekofneko•26m ago•0 comments

France passes bill to ban social media use by under-15s

https://www.rte.ie/news/europe/2026/0127/1555251-france-social-media-ban/
3•austinallegro•28m ago•0 comments

Right of First Refusal

https://en.wikipedia.org/wiki/Right_of_first_refusal
1•wslh•32m ago•0 comments

Fire Kristi Noem into the Sun

https://www.nationalreview.com/2026/01/fire-kristi-noem-into-the-sun/
4•petethomas•36m ago•0 comments

Garry Kasparov on Minnesota Killing and ICE

https://twitter.com/kasparov63/status/2015126502845587957
3•wslh•38m ago•0 comments

Show HN: Walk and drive through OpenStreetMap in 3D

https://bilalba.github.io/osmexplorer/
1•bilalba•41m ago•1 comments

Math Inspector – A Visual Programming Environment for Scientific Computing

https://mathinspector.com/
1•vismit2000•41m ago•0 comments

TikTok alternative Skylight soars to 380K+ users after TikTok US deal finalized

https://techcrunch.com/2026/01/26/tiktok-alternative-skylight-soars-to-380k-users-after-tiktok-u-...
2•DavideNL•41m ago•0 comments

Show HN: LinkLens – Document and link tracking in one dashboard

https://www.linklens.tech/
1•donghyunkim_bld•45m ago•0 comments

Police chatbots in UK could free up equivalent of 3k police officers

https://www.thetimes.com/uk/politics/article/police-chatbots-will-respond-to-non-urgent-queries-h...
2•petethomas•46m ago•1 comments

Okay, so why are lexers even needed? [video]

https://www.youtube.com/watch?v=MBpMYTTEvLU
1•edward28•48m ago•0 comments

Doing the thing is doing the thing

https://www.softwaredesign.ing/blog/doing-the-thing-is-doing-the-thing
3•prakhar897•49m ago•0 comments

Show HN: Engroles.com – Verified, Active SWE Listings from Recruiters

https://engroles.com/
1•partypete•49m ago•0 comments

Show HN: Nvidia Nemotron-Personas-Singapore Dataset for Sovereign AI

https://huggingface.co/datasets/nvidia/Nemotron-Personas-Singaporehttps://huggingface.co/datasets...
1•repeator2•51m ago•0 comments

One developer used Claude to build a memory-safe extension of C

https://www.theregister.com/2026/01/26/trapc_claude_c_memory_safe_robin_rowe/
2•rurban•57m ago•1 comments

Show HN: Jiss – A community-powered LLM API I built for open models

https://jiss.ai
1•almans•58m ago•0 comments