frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

To Build a Fire

https://www.newyorker.com/magazine/2026/02/09/to-build-a-fire
1•mitchbob•1m ago•1 comments

MicroVM Sandboxes for Claude Code and Gemini from Docker

https://www.docker.com/products/docker-sandboxes/
1•srini-docker•1m ago•0 comments

A Learning Community for AI Agents

https://learnclaw.net
1•victor_cl•1m ago•0 comments

Self-Hosting Guide to Alternatives: Notion

https://selfh.st/alternatives/notion/
1•pavel_lishin•2m ago•0 comments

Show HN: FrameVault – a desktop-first photo backup tool built after losing data

https://cameratrician.com/framevault/
1•arbopa•3m ago•0 comments

Show HN: Img-src – $5/month image CDN with on-the-fly transforms via URL params

https://img-src.io
1•taehun•3m ago•0 comments

50 years ago, a young Bill Gates took on the 'software pirates'

https://thenewstack.io/50-years-ago-a-young-bill-gates-took-on-the-software-pirates/
1•naves•3m ago•0 comments

Emacs Hugo Theme

https://github.com/ArthurHeymans/hugo-emacs-theme
1•self•4m ago•1 comments

Monitoring and engaging in social media conversations during a crisis

https://www.tandfonline.com/doi/full/10.1080/23311975.2015.1084978
1•Caarticles•4m ago•0 comments

Show HN: Vibecode Together – StumbleUpon for Vibe-coded projects

https://vibecodetogether.flow.club/
2•dtran•5m ago•0 comments

AI SEC startup CEO posts a job. Deepfake candidate applies, inner turmoil ensues

https://www.theregister.com/2026/02/01/ai_security_startup_ceo_posts/
1•jjoachim3•6m ago•0 comments

Chaldean/Aramaic Flashcards [pdf]

https://www.culturaldiversity.com.au/files/multilingual-resources/2025/01/Chaldean-Bilingual-Phra...
1•marysminefnuf•6m ago•0 comments

Show HN: Drift FM – Ambient Mood Radio (Go, SQLite, Vanilla JavaScript)

https://drift.1mb.dev
1•vnykmshr•6m ago•0 comments

What You Should Know About Facebook CEO Mark Zuckerberg's Senate Hearing

https://blog.acton.org/archives/101128-explainer-what-you-should-know-about-facebook-ceo-mark-zuc...
1•Caarticles•7m ago•0 comments

Goodhart's Law: When a measure becomes a target, it ceases to be a good measure

https://en.wikipedia.org/wiki/Goodhart%27s_law
1•insuranceguru•7m ago•0 comments

Show HN: A small API for generating reliable PDFs using LaTeX

https://texapi.ovh/
2•MrGrzybek•8m ago•0 comments

OpenText to Divest Vertica for US$150M

https://www.morningstar.com/news/pr-newswire/20260202la75996/opentext-to-divest-vertica-for-us150...
1•zX41ZdbW•9m ago•0 comments

llm-d 0.4: Achieve SOTA performance across accelerators

https://llm-d.ai/blog/llm-d-v0.4-achieve-sota-inference-across-accelerators
1•teleforce•10m ago•0 comments

Overpaying me after using illegal plugins

https://priyatham.in/en/post/pirate-plugins/
1•vasquezempereur•10m ago•0 comments

Show HN: A Cursor plugin to output OpenTelemetry for logging / observability

https://github.com/LangGuard-AI/cursor-otel-hook
1•brunes•10m ago•0 comments

The largest number representable in 64 bits

https://tromp.github.io/blog/2026/01/28/largest-number-revised
1•tromp•10m ago•0 comments

/Top4

https://topfour.net
1•surprisetalk•11m ago•0 comments

From 1 to n: Multiplayer Game Design (2018)

https://www.raphkoster.com/games/presentations/from-1-to-n-multiplayer-game-design/
1•surprisetalk•11m ago•0 comments

Stop incentivizing surface parking lots

https://progressandpoverty.substack.com/p/stop-incentivizing-surface-parking
2•surprisetalk•11m ago•0 comments

Hybrid Concolic Testing with Large Language Models for Guided Path Exploration

https://arxiv.org/abs/2601.12274
1•PaulHoule•11m ago•0 comments

Kolakoski Sequence

https://en.wikipedia.org/wiki/Kolakoski_sequence
1•surprisetalk•11m ago•0 comments

Roami: Outing Research Agent

https://roami.ca/
1•idewanck•12m ago•1 comments

Show HN: Histomap Reborn – Interactive visualization of world history

https://histomap.robennals.org/
1•robotelvis•13m ago•0 comments

A decade of open innovation: Ten years of Microsoft and Red Hat partnership

https://azure.microsoft.com/en-us/blog/a-decade-of-open-innovation-celebrating-10-years-of-micros...
1•teleforce•13m ago•0 comments

RCC: A boundary theory explaining why LLMs hallucinate and planning collapses

http://www.effacermonexistence.com/rcc-hn
2•noncentral•14m ago•2 comments