frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

First 12 Minutes of MTV (1981) [video]

https://www.youtube.com/watch?v=oVrEzH9gkZk
1•walterbell•1m ago•0 comments

Worst of Breed Software

https://worstofbreed.net/
1•facundo_olano•2m ago•0 comments

I Fed Claude 7 Years of Daily Journals. It Showed Me the Future of AI

https://medium.com/swlh/i-fed-claude-7-years-of-daily-journals-it-showed-me-the-future-of-ai-2c13...
1•ako•4m ago•0 comments

Kalpa Desktop

https://kalpadesktop.org/
1•Tomte•13m ago•0 comments

Show HN: Persistent Memory for Claude Code (MCP)

https://github.com/DiaaAj/a-mem-mcp
2•AttentionBlock•13m ago•0 comments

Amber Features 2026 for Java

https://mail.openjdk.org/pipermail/amber-spec-experts/2026-January/004306.html
2•joe_mwangi•14m ago•0 comments

Claude Code Unable to generate a AGPLv3 license due to content filtering policy

https://github.com/anthropics/claude-code/issues/12705
4•mickdarling•14m ago•2 comments

How the hell are you supposed to have a career in tech in 2026?

https://www.anildash.com/2026/01/05/a-tech-career-in-2026/
4•momentmaker•16m ago•0 comments

Sinclair C5

https://en.wikipedia.org/wiki/Sinclair_C5
5•jszymborski•16m ago•0 comments

Working with multiple repositories in AI tools sucks

https://www.ricky-dev.com/coding/2026/01/agentic-tooling-across-multiple-repositories/
2•DigitallyBorn•16m ago•1 comments

CQ Serenade [pdf]

https://g4dmp.co.uk/cq_music.pdf
1•austinallegro•16m ago•0 comments

39C3 – Asahi Linux – Porting Linux to Apple Silicon – Sven Peter

https://www.youtube.com/watch?v=GWHWWuxvSn0
2•tux1968•17m ago•1 comments

Rare first Superman comic once stolen from Nicolas Cage sells for $15M

https://www.bbc.com/news/articles/cly95lpwl1ro
2•1659447091•20m ago•0 comments

Observability with ClickHouse (2023)

https://boristane.com/talks/observability-with-clickhouse/
2•tosh•20m ago•0 comments

Visualising RAG

https://old.reddit.com/r/LocalLLaMA/comments/1q998is/visualizing_rag_part_2_visualizing_retrieval/
1•regisb•22m ago•1 comments

Show HN: I built a DLL to stop Excel/Word from spawning PowerShell shells

https://github.com/subhashdasyam/MalDocShield
1•dxsecarch•22m ago•0 comments

Linus Torvalds Uses Google Antigravity

https://github.com/torvalds/AudioNoise/blob/main/README.md
2•xnx•22m ago•0 comments

Accessibility Concerns Over Bakerl0.0 Line Advertiser's Rebrand

https://www.bbc.co.uk/news/articles/c86v3e7xlejo
2•susam•27m ago•0 comments

AgentRoam: Watch GPT-5.2 control movement, camera and selfies in Watch Dogs 2

https://www.youtube.com/watch?v=XTYWewHz-Tg
2•dandelionv1bes•28m ago•0 comments

Neon (serverless Postgres) transitions away from open source

https://github.com/neondatabase/neon/issues/12843
2•crispair•30m ago•2 comments

Defrosting using low-energy surface heating

https://www.betterfrost.com/
1•unwind•34m ago•0 comments

Show HN: Stillmail. minimalist email app for friends

https://stillmail.app
1•mustafaiste•35m ago•2 comments

Techrastination

https://ckardaris.github.io/blog/2026/01/10/techrastination.html
2•ckardaris•36m ago•0 comments

Common misunderstandings about large software companies

https://philipotoole.com/common-misunderstandings-about-large-software-companies/
3•otoolep•37m ago•1 comments

An explanation of performance degradation through false sharing [video]

https://www.youtube.com/watch?v=WIZf-Doc8Bk
1•zahlman•37m ago•1 comments

Are There Any Similar Sites Like Downdetector?

2•nomadfounder•38m ago•0 comments

The First 'Apple Silicon': The Aquarius Processor Project

https://thechipletter.substack.com/p/the-first-apple-silicon-the-aquarius-7cb
1•rbanffy•39m ago•1 comments

Show HN: Makers.page – A link-in-bio for founders with a "slot leasing" protocol

1•alexcloudstar•40m ago•0 comments

When_Sysadmins_Ruled_the_Earth

https://craphound.com/overclocked/Cory_Doctorow_-_Overclocked_-_When_Sysadmins_Ruled_the_Earth.html
1•b112•41m ago•0 comments

xByte, the Pay-per-Byte content-agnostic infra

https://github.com/Arvmor/xByte
3•Arvmor•44m ago•0 comments