frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Steam Link Expands to Apple Vision Pro in Beta

https://www.tuaw.com/2026/04/11/steam-link-expands-to-apple-vision-pro-in-beta/
2•zeristor•2m ago•0 comments

United's Unique Hub in the Pacific

http://www.flightsinasia.com/update/article/Uniteds-Unique-Hub-in-the-Pacific/
1•kevmo314•4m ago•0 comments

Show HN: Waffle – Native macOS terminal that auto-tiles sessions into a grid

https://waffle.baby
1•olleeolleeollee•6m ago•0 comments

How do the microplastics in our bodies affect our health?

https://www.bbc.com/future/article/20250723-how-do-the-microplastics-in-our-bodies-affect-our-health
1•strogonoff•6m ago•0 comments

Show HN: The Musical Manifold [pdf]

https://esenbilproductions.replit.app/The_Musical_Manifold.pdf
1•ersinesen•9m ago•0 comments

Compact Compact Language Detector

https://www.andriydruk.com/post/compact-compact-language-detector/
1•andriydruk•12m ago•0 comments

Apollo in Real Time

https://apolloinrealtime.org/11/
1•rvnx•13m ago•0 comments

MySQL 9.7.0 vs. sysbench on a small server

http://smalldatum.blogspot.com/2026/04/mysql-970-vs-sysbench-on-small-server.html
1•gsky•19m ago•0 comments

South Korea introduces universal basic mobile data access

https://www.theregister.com/2026/04/10/south_korea_data_access_universal/
2•saikatsg•19m ago•0 comments

Slides (Hypnotic Video About a Dude's Slides and Slide Projector)

https://www.youtube.com/watch?v=hZhMAtHoU20
1•OhMeadhbh•21m ago•1 comments

Plannex

https://plannex.app/
1•Novakinify•21m ago•0 comments

Spooky-connect4: a Rust/Python library with variable board sizes

https://github.com/snowdrop4/spooky-connect4
1•drw•22m ago•0 comments

Spooky-chess: a Rust/Python library with variable board sizes

https://github.com/snowdrop4/spooky-chess
1•drw•23m ago•0 comments

Bitcoin miners are losing $19,000 on every BTC produced as difficulty drops 7.8%

https://www.coindesk.com/markets/2026/03/22/bitcoin-miners-are-losing-usd19-000-on-every-btc-prod...
27•PaulHoule•24m ago•16 comments

TraceFix – Paste a Linux/SSH log error, get the root cause and exact fix command

https://tracefix.vercel.app/
1•skillsettler•24m ago•0 comments

Cotypist

https://cotypist.app/
1•saikatsg•25m ago•0 comments

Shipped a 66-ticket Architecture Epic autonomously with a new Coding Agent setup

https://widal.substack.com/p/we-shipped-a-66-ticket-architecture
2•niwid•25m ago•0 comments

SVG in the Age of AI

https://svg.new/blog/svg-in-the-age-of-ai
4•swazzy•26m ago•0 comments

Show HN: Lovinghate – Share what you love and hate

https://lovinghate.com/
1•goshua•26m ago•0 comments

Show HN: An offline, privacy-first Pomodoro timer with 18 ambient soundscapes

https://www.adribyte-studio.com/mobile-apps/focusscape
1•AdriByte-Studio•28m ago•0 comments

Efficacy of front-of-package nutrient labels: a randomised controlled trial

https://www.thelancet.com/journals/lancet/article/PIIS2468-2667(26)00027-7/fulltext
1•PaulHoule•30m ago•0 comments

Brightcast.news

https://www.brightcast.news
1•Tommienbp•30m ago•0 comments

Free landing page review tool

https://splitsense.ai/tools/free-landing-page-review
1•george-field•30m ago•0 comments

Microcontrollers for a Lightbulb Turned Project of IoT Button Devices [video]

https://www.youtube.com/watch?v=ljrKFFjFT04
1•laserlight•31m ago•0 comments

Terry Tao "How to think like a mathematician" [video]

https://www.youtube.com/watch?v=kRcro90Aj0w
3•tzury•33m ago•1 comments

Microsoft Upgrades Its WSL2 Kernel Against Linux 6.18 LTS

https://www.phoronix.com/news/Linux-6.18-LTS-Microsoft-WSL2
3•Brajeshwar•34m ago•0 comments

Why your next mobile app is probably headless

https://tuananh.net/2026/03/18/why-your-next-mobile-app-is-probably-headless/
1•PaulHoule•34m ago•0 comments

Polymarket's $269M Question: Did U.S. Forces 'Enter' Iran?

https://www.wsj.com/world/middle-east/polymarket-iran-war-bets-975909a3
2•codechicago277•36m ago•0 comments

I researched Google Antigravity IDE quota failures and proposed a product fix

https://github.com/VIKAS9793/antigravity-continuity-engine
1•Vikas9793•38m ago•0 comments

Csvql – SQL queries on CSV files, 9x faster than DuckDB, written in Zig (ShowHN)

https://github.com/melihbirim/csvql
2•melih1im•38m ago•0 comments