frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

The Future of Text Layout Is Not CSS

https://twitter.com/_chenglou/status/2037713766205608234
1•california-og•3m ago•1 comments

How Accurate is this? [No Access to X:(]

https://twitter.com/CLG98264897/status/2037312460433109106
1•SilentM68•3m ago•0 comments

While one partner sleeps, another vibe codes

https://www.businessinsider.com/claude-gap-relationship-vibe-code-couples-2026-3
1•mlaretallack•7m ago•0 comments

The United States is driving a public health emergency of international concern

https://www.bmj.com/content/392/bmj-2026-089474
2•KnuthIsGod•11m ago•0 comments

EU Commission, Enisa, and DG Digital Services Breached by ShinyHunters

https://twitter.com/IntCyberDigest/status/2038038430752374888
1•CountGeek•11m ago•0 comments

Why question-space can't be baked into LLM weights (preprint)

https://zenodo.org/records/19305025
1•h_hasegawa•15m ago•1 comments

Narcissistic grandiosity predicts greater involvement in LGBTQ activism

https://www.psypost.org/narcissistic-grandiosity-predicts-greater-involvement-in-lgbtq-activism/
1•Tomte•16m ago•0 comments

Zuck's obsession with VR lost him AI leadership

https://twitter.com/futurejurvetson/status/2037925810208960965
1•MrBuddyCasino•17m ago•0 comments

Former NJ AG's Firm Challenges Big Tech's 'Profit Ahead of Public Safety' Ethos

https://www.law.com/therecorder/2026/03/20/openai-targeted-as-former-new-jersey-ags-new-firm-chal...
1•1vuio0pswjnm7•22m ago•0 comments

Disgraced fraudster Elizabeth Holmes caught a break; prosecutors aren't happy

https://nypost.com/2026/03/27/business/disgraced-theranos-fraudster-elizabeth-holmes-just-caught-...
2•1vuio0pswjnm7•35m ago•0 comments

Whats the most surprising business process you've automated with OpenClaw?

1•dhruvkar•38m ago•0 comments

List of Common Misconceptions

https://en.wikipedia.org/wiki/List_of_common_misconceptions
2•thedrexster•41m ago•0 comments

Human brain operates near, but not at, the critical point

https://phys.org/news/2026-03-human-brain-critical.html
2•yoquan•44m ago•0 comments

Fedora 44 will automatically make your Windows games run faster

https://www.xda-developers.com/fedora-44-will-automatically-make-your-windows-games-run-faster-no...
2•Alupis•46m ago•0 comments

WTO reforms talks stalled amid U.S.-India digital services taxation deadlock

https://www.reuters.com/world/india/wto-talks-stalled-going-into-final-day-amid-us-india-e-commer...
2•alephnerd•49m ago•0 comments

Hertz and Hearts – PC HRV biofeedback for chest-strap ECG (OpenHRV fork)

https://github.com/JoelAtHome/HertzAndHearts
1•J_Kobe•52m ago•0 comments

Apple issues urgent lock screen warnings for unpatched iPhones and iPads

https://securityaffairs.com/190109/security/apple-issues-urgent-lock-screen-warnings-for-unpatche...
3•WaitWaitWha•56m ago•0 comments

Emergency Microsoft, Oracle patches point to wider cyber issues

https://www.computerweekly.com/news/366640648/Emergency-Microsoft-Oracle-patches-point-to-wider-c...
2•smurda•57m ago•0 comments

Pentagon prepares for weeks of ground operations in Iran

https://www.washingtonpost.com/national-security/2026/03/28/trump-iran-ground-troops-marines/
6•Jimmc414•57m ago•2 comments

ReadyPC – open-source Rust PC Optomizer

https://github.com/Gloom-Team/ReadyPC/releases/tag/Latest
1•asdadaZ•58m ago•0 comments

Improving My C Build System with Zig

https://louislefebvre.net/tech/zig-gcc-replace/
1•louislef299•58m ago•0 comments

OpenYak – An open-source Cowork that runs any model and owns your filesystem

https://github.com/openyak/desktop
23•wangzhangwu•1h ago•4 comments

The Fastest Man Alive? [video]

https://www.youtube.com/shorts/R7OoEXaOVY0
1•SilentM68•1h ago•0 comments

How to Do Any Work

https://drive.google.com/uc?id=1wurJsO1vZYiynrTxDLroiQX2fBnKmldo&export=download
1•waseyjamal•1h ago•1 comments

Generalized Linear Model

https://en.wikipedia.org/wiki/Generalized_linear_model
2•azhenley•1h ago•0 comments

Data Centers Under Fire: A Systemic Security Challenge

https://www.datacenterknowledge.com/physical-security/data-centers-under-fire-a-growing-critical-...
1•WaitWaitWha•1h ago•0 comments

Mark Zuckerberg texted Elon Musk to offer help with DOGE

https://techcrunch.com/2026/03/28/mark-zuckerberg-texted-elon-musk-to-offer-help-with-doge/
3•toomanyrichies•1h ago•0 comments

Thinking in the Margins

https://theamericanscholar.org/thinking-in-the-margins/
1•SegfaultSeagull•1h ago•0 comments

The Revenge of the Data Scientist

https://hamel.dev/blog/posts/revenge/
1•prabal97•1h ago•0 comments

Eval-Driven Development: Applying TDD Principles to AI Agent Prompts

https://iris-eval.com/blog/eval-driven-development
1•iparent•1h ago•0 comments