frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Code signing Windows apps with Azure Artifact service

https://devclass.com/2026/01/14/code-signing-windows-apps-may-be-easier-and-more-secure-with-new-...
1•todsacerdoti•54s ago•0 comments

Why TikTok's first week of American ownership was a disaster

https://www.theguardian.com/technology/2026/feb/01/tiktok-first-week
1•n1b0m•1m ago•0 comments

Ada and Zangemann – A Tale of Software, Skateboards, and Raspberry Ice Cream

https://fsfe.org/activities/ada-zangemann/
1•janisz•2m ago•0 comments

Ask HN: How do you handle auth when AI dev agents spin up short-lived apps?

1•NBenkovich•3m ago•0 comments

Show HN: Moltbot Art – AI agents draw art with code, not prompts

https://www.moltbotart.com
1•fkysly•5m ago•0 comments

Opinionated Read: How AI Impacts Skill Formation

https://www.sicpers.info/2026/02/opinionated-read-how-ai-impacts-skill-formation/
1•grahamlee•5m ago•0 comments

Be KVM, Do Fraud

https://blog.grumpygoose.io/be-kvm-do-fraud-8ab523d26c9d
1•rzk•6m ago•0 comments

ChatGPT-CLI: A Simple ChatGPT CLI That Stays Out of Your Way

https://github.com/umbertocicciaa/chatgpt-cli
1•umbertocicciaa•7m ago•1 comments

Show HN: Noisefloor – Letterboxd for your music collection

https://www.noisefloor.fm/
2•ljsdev•8m ago•1 comments

I don't use Google Maps in Amsterdam [video]

https://www.youtube.com/watch?v=csHdwHTteOw
1•wtf42•9m ago•0 comments

Wikipedia Template: Committed Identity

https://en.wikipedia.org/wiki/Template:Committed_identity
1•susam•11m ago•0 comments

NHK, university researchers develop power-generating OLED display device

https://www3.nhk.or.jp/nhkworld/en/news/20260201_06/
1•ncoelhosantos•13m ago•0 comments

Turning Karpathy's Autoregressive Baby GPT into Diffusion GPT Step by Step

https://colab.research.google.com/github/ash80/diffusion-gpt/blob/master/The_Annotated_Discrete_D...
1•ash_at_hny•20m ago•0 comments

Google I/O 2013 – Advanced Go Concurrency Patterns [video]

https://www.youtube.com/watch?v=QDDwwePbDtw
1•bmacho•25m ago•0 comments

Show HN: Rubber Duck Committee – Multi-persona AI debugging with voting

https://rubber-duck-committee.vercel.app/
1•r-leyshon•26m ago•0 comments

A separatist group is asking for Trump's help to split from Canada

https://www.cnn.com/2026/01/30/americas/alberta-independence-trump-canada-intl-hnk
4•breve•29m ago•1 comments

Show HN: We Ran a Live Red-Team Attack on OpenClaw Agents

https://gobrane.com/observing-adversarial-ai-lessons-from-a-live-openclaw-agent-security-audit/
1•udit_50•31m ago•0 comments

What happens when OpenClaw agents attack each other

1•udit_50•32m ago•0 comments

Moss Just Survived a Full Year Outside the International Space Station

https://www.vice.com/en/article/moss-survives-in-the-vacuum-of-space/
1•stared•34m ago•0 comments

OpenAI Investment Was 'Never a Commitment,' Nvidia's Huang Says

https://www.bloomberg.com/news/articles/2026-02-01/openai-investment-was-never-a-commitment-nvidi...
2•zerosizedweasle•35m ago•0 comments

FOSDEM 2026 – Live Streaming

https://fosdem.org/2026/schedule/streaming/
1•birdculture•35m ago•0 comments

All politics is digital politics (serie of 3 articles)

https://www.theguardian.com/commentisfree/series/all-politics-is-digital-politics
2•giuliomagnifico•38m ago•0 comments

Australian plumber is a YouTube sensation

https://arstechnica.com/culture/2026/01/australian-plumber-is-a-youtube-sensation/
2•nomilk•38m ago•0 comments

1 GB memory reduction for long Claude Code sessions

https://twitter.com/jarredsumner/status/2017825694731145388
1•tosh•43m ago•0 comments

Claude Code: connect to a local model when your quota runs out

https://boxc.net/blog/2026/claude-code-connecting-to-local-models-when-your-quota-runs-out/
2•fugu2•44m ago•0 comments

How I Transformed My Life in 2025

https://bayramovanar.substack.com/p/how-i-transformed-my-life-in-2025
2•Bayramovanar•45m ago•1 comments

Normalcy bias: it's not cool to overreact

https://www.okdoomer.io/its-not-cool-to-overreact/
1•fanf2•46m ago•0 comments

Moltbook are exposing their database to the public

https://twitter.com/theonejvo/status/2017732898632437932
3•startupfreak•46m ago•0 comments

OpenClaw and Moltbook let attackers walk through the front door

https://the-decoder.com/openclaw-formerly-clawdbot-and-moltbook-let-attackers-walk-through-the-fr...
2•startupfreak•47m ago•0 comments

AI in the Exam Room – Free curriculum for safe medical AI use

https://aiintheexamroom.com/
1•drjcfmd•47m ago•1 comments