frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

My Thoughts on AI

https://sarah.engineer/posts/thoughts-on-ai/
2•cod1r•9m ago•0 comments

Show HN: Seedance2 – Stop "prompt guessing" and start directing AI video

https://seedancevideo.app/
1•echoadam•9m ago•0 comments

Scientists Found a Mysterious Cave Full of Million-Year-Old Fossils

https://www.popularmechanics.com/science/archaeology/a70190789/island-fossils-new-zealand/
1•naves•10m ago•0 comments

Show HN: Business card scanner with frame selection, dedupe, and vCard export

https://github.com/vassiliylakhonin/bizcard-ai-scanner
1•vassilbek•13m ago•0 comments

LightRag / GraphRag Implementation in Rust

https://github.com/raphaelmansuy/edgequake
1•raphaelmansuy•16m ago•0 comments

Show HN: Claude Meter – macOS menu bar app to track your Claude Code usage limit

https://github.com/puq-ai/claude-meter
5•aliyilmaz-co•22m ago•2 comments

MechaEpstein-8000

https://huggingface.co/ortegaalfredo/MechaEpstein-8000-GGUF
1•aortega•25m ago•1 comments

Europe's 'painful' realisation it must be bolder with US: security report

https://www.theguardian.com/world/2026/feb/09/europe-us-munich-security-conference-report
2•saubeidl•26m ago•0 comments

Show HN: Konform Browser v140.7.0-108

https://codeberg.org/konform-browser/source/releases/tag/140.7.0.108
1•konform•29m ago•0 comments

Structure Beats Prose: Specs for Coding Agents That Work

https://medium.com/@stefanvanegmond/structure-beats-prose-specs-for-coding-agents-that-actually-w...
1•stefanve•31m ago•0 comments

Design is dead, it's all evolution now

https://ilyabirman.net/meanwhile/all/design-vs-evolution/
1•rozboris•32m ago•0 comments

Mistral.rs – Fast, zero-config multimodal LLM inference for a variety of models

https://github.com/EricLBuehler/mistral.rs
2•Curiositry•33m ago•2 comments

Benchmarking Claude C Compiler

https://dineshgdk.substack.com/p/benchmarking-claude-c-compiler
1•dinesh_gdk•33m ago•1 comments

What Moltbook alternatives are doing some actual constructive work?

1•Fh_•34m ago•0 comments

Show HN: PhoneClaw

https://github.com/rohanarun/phoneclaw
1•GPUboy•34m ago•0 comments

Towards a Standard for JSON Document Databases

https://arxiv.org/abs/2509.12189
1•ingve•38m ago•0 comments

Brutalist Southbank Centre Listed

https://www.architectsjournal.co.uk/news/brutalist-southbank-centre-finally-listed-after-35-years...
2•daverol•41m ago•0 comments

Sandboxing Systemd Services

https://ejaaskel.dev/sandboxing-systemd-services/
1•weinzierl•43m ago•0 comments

Ask HN: Starting my own startup to increase compute density

2•isubasinghe•43m ago•0 comments

Linux USB iPhone Tethering

https://wiki.archlinux.org/title/IPhone_tethering
4•walterbell•47m ago•0 comments

Why the Internet Is Terrified of London

https://www.youtube.com/watch?v=uDkyP37JgY0
2•robin_reala•54m ago•0 comments

AI Coding Is a Framework–Use It Like a Library

https://www.piglei.com/articles/en-ai-coding-is-a-framework/
2•zdyxry•56m ago•0 comments

A one-prompt attack that breaks LLM safety alignment

https://www.microsoft.com/en-us/security/blog/2026/02/09/prompt-attack-breaks-llm-safety/
1•weinzierl•59m ago•0 comments

Subscription plans for YouTube TV are now cheaper

https://www.neowin.net/news/good-news-for-youtube-tv-users-cheaper-plans-are-now-available/
1•bundie•1h ago•0 comments

Show HN: YAML-based security framework for CDN edge (CloudFront / Cloudflare)

https://github.com/albert-einshutoin/cdn-security-framework
1•einshutoin•1h ago•1 comments

How to Keep What You Built Together

https://claudepress.substack.com/p/how-to-keep-what-you-built-together
1•Paodim•1h ago•0 comments

Composer 1.5

https://cursor.com/blog/composer-1-5
2•albingroen•1h ago•1 comments

A few design decisions for a new chat platform

https://sporks.space/2026/02/10/a-few-design-decisions-for-a-new-chat-platform/
2•todsacerdoti•1h ago•0 comments

Show HN: Canon-C – a semantic C library

https://github.com/Fikoko/Canon-C
2•Fikoko•1h ago•2 comments

Ask HN: How do you maximize your luck surface area?

2•tiny-automates•1h ago•2 comments