frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Anthropic Labs

https://www.anthropic.com/news/introducing-anthropic-labs
1•kerim-ca•44s ago•0 comments

The Vampire Paradox

https://worldsensorium.com/the-vampire-paradox/
1•dnetesn•1m ago•0 comments

We're Evolving Beyond This Rock

https://nautil.us/were-evolving-beyond-this-rock-right-now-1261129/
1•dnetesn•2m ago•0 comments

Show HN: My Own AWS

https://blog.sanyamgarg.com/#/posts/private-cloud
1•sammylis•2m ago•0 comments

Show HN: ProtocolSoup – Interactive Sandbox for OAuth, OIDC, SAML, Spiffe, SSF

https://protocolsoup.com/
2•ParleSec•4m ago•0 comments

Grok will be integrated into Pentagon networks, Hegseth says

https://www.theguardian.com/technology/2026/jan/13/elon-musk-grok-hegseth-military-pentagon
2•voxleone•6m ago•0 comments

We let an AI help us decide which startups to invest in for 6 months

https://theventures.substack.com/p/we-let-an-ai-help-us-decide-which
1•jefflee0127•7m ago•0 comments

'Hermès of durian': Luxury fruit cashing in on China's billion-dollar appetite

https://www.bbc.com/news/articles/cz7ndzw28v4o
1•bookofjoe•8m ago•1 comments

I built an email client with local AI. open source it?

1•eibrahim•8m ago•0 comments

The Wine That Doesn't Have a Name Yet: Inside the Chemistry of Co-Fermention

https://fruitwine.substack.com/p/the-wine-that-doesnt-have-a-name
2•djrivard•8m ago•0 comments

Whenwords: A relative time formatting library, with no code

https://github.com/dbreunig/whenwords
1•simonpure•8m ago•0 comments

Responsible Disclosure: Chimoney Android App and KYCaid

https://shkspr.mobi/blog/2026/01/responsible-disclosure-chimoney-android-app-and-kycaid/
2•ColinWright•9m ago•0 comments

ChatPRD/lennys-podcast-transcripts: Transcripts from all Lenny's podcasts

https://github.com/ChatPRD/lennys-podcast-transcripts
1•emreb•10m ago•0 comments

Ask HN: Would you consider an explicit AST/NNF logic engine a "Core of XAI"?

https://TreeOfKnowledge.eu
1•JAnicaTZ•11m ago•1 comments

I Built Videos with Soro2

https://soro2.net
1•xbaicai•11m ago•1 comments

Show HN: GitHug – Discover new GitHub users

https://githug.link
1•daviducolo•13m ago•0 comments

Zuckerberg Launches Meta Compute, plans to build hundreds of gigawatts

https://www.threads.com/@zuck/post/DTa3-B1EbTp
1•ppsreejith•15m ago•1 comments

Show HN: Run LLMs in Docker for any language without prebuilding containers

https://github.com/mheap/agent-en-place
2•mheap•16m ago•0 comments

Show HN: Arche Resizer – a fast browser tool to resize images without uploads

https://arche-resizer.vercel.app/
1•SRMohitkr•16m ago•0 comments

Xinjiang whistleblower faces deportation to China

https://www.dw.com/en/xinjiang-whistleblower-faces-deportation-to-china-lawyer/a-75475876
2•perihelions•18m ago•0 comments

Interrail/Eurail data security breach

https://www.interrail.eu/en/ni/data-security-incident
1•beanslover•18m ago•0 comments

How to Find the Real Decision Makers in Nova Scotia Government

https://scotiasignal.ca/blog/how-to-find-decision-makers-nova-scotia-government
1•5eva•19m ago•0 comments

Fast and flexible observability with canonical log lines (2019)

https://stripe.com/blog/canonical-log-lines
1•tosh•19m ago•0 comments

AI Hairstyle Changer

https://hairstyleaichanger.com/
1•Fsen•20m ago•1 comments

Ask HN: What's your opinion on a VR/XR business?

1•izwasm•20m ago•0 comments

NCSA (National Center for Supercomputing): The unsung hero of Internet history

https://dfarq.homeip.net/ncsa-the-unsung-hero-of-internet-history/
2•giuliomagnifico•21m ago•0 comments

Becoming a Whorelord: The Overly Analytical Guide to Escorting (2021)

https://knowingless.com/2021/10/19/becoming-a-whorelord-the-overly-analytical-guide-to-escorting/
2•KolmogorovComp•22m ago•0 comments

Wikipedia founder Jimmy Wales on trust and optimism

https://www.nature.com/articles/d41586-026-00083-0
1•sohkamyung•23m ago•0 comments

Show HN: Claude Code Supervisor – Auto review and prevent agent stop

https://github.com/guyskk/claude-code-supervisor
1•guyskk•24m ago•0 comments

New Workday Research: Companies Are Leaving AI Gains on the Table

https://investor.workday.com/news-and-events/press-releases/news-details/2026/New-Workday-Researc...
1•_____k•25m ago•0 comments