frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Ask HN: Which repos have merged PRs worth reading?

1•justabuilder•3m ago•0 comments

RoyalSonic – Affordable business email and groupware suite

https://www.royalsonic.com/shop-2/
1•dhamanij•5m ago•0 comments

Which repos have merged PRs worth reading?

1•justabuilder•5m ago•0 comments

Does Computer Science Need Computers?

https://www.quantamagazine.org/does-computer-science-need-computers-20260828/
1•Michelangelo11•5m ago•0 comments

Spark: Sparklines in your shell

https://git.zx2c4.com/spark/about/
1•hskimse•6m ago•0 comments

Java at 30 Essay [pdf]

https://bracha.org/java_at_30_essay.pdf
1•__patchbit__•10m ago•0 comments

We built this after an AI agent misread a risk signal and moved $1.2M in trades

https://runplane.ai
1•runplane•10m ago•0 comments

Nvidia's AI advantage is moving beyond the GPU

https://techcrunch.com/2026/08/29/nvidias-ai-advantage-is-moving-beyond-the-gpu/
1•01-_-•11m ago•0 comments

macOS MLX Control Center v0.4 Released

https://github.com/mypbs/mac-mlx-control-center
1•hashz•11m ago•0 comments

Show HN: Bolnee-Chat – Self Hosted Chatbot Integration in Your Business Website

https://github.com/AniketWathore/bolnee-chat
1•AniketWathore•12m ago•0 comments

Workers in their 40s, 50s and 60s are the most positive about AI

https://www.bloomberg.com/news/articles/2026-08-27/older-workers-are-more-upbeat-about-ai-than-20...
1•giuliomagnifico•12m ago•0 comments

Memo to Ridley Scott: no one needs more Alien: Covenant movies

https://www.theguardian.com/film/2026/aug/28/ridley-scott-alien-covenant-follow-up
2•dtnm•13m ago•1 comments

Exeter University approves deal with Saudi Arabia to train military officers

https://www.theguardian.com/education/2026/aug/29/exeter-university-approves-deal-with-saudi-arab...
1•phoebos•14m ago•0 comments

Fixing Emacs Dired Defaults: Settings for Better File Management

https://www.jamescherti.com/emacs-dired-configuration/
1•signa11•15m ago•0 comments

Everyone Should Build Their Own Network Stack

https://blog.lyc8503.net/en/post/dn42-2-dnet/
1•uneven9434•16m ago•0 comments

70% of new drugs approved by FDA in 2024 were based on a single study

https://www.cidrap.umn.edu/public-health/more-two-thirds-new-drugs-approved-fda-2024-were-based-s...
1•giuliomagnifico•17m ago•0 comments

Anthropic Says Its Market Is $30T, Same as US GDP

https://247wallst.com/investing/2026/08/26/anthropic-says-its-market-is-30-trillion-same-as-us-gdp/
1•mgh2•25m ago•0 comments

General resolution: LLM usage in Debian: Results

https://lists.debian.org/debian-devel-announce/2026/08/msg00005.html
1•ckastner•26m ago•0 comments

Show HN: Lexino - Build five-letter words with letter dominoes

https://github.com/skorotkiewicz/lexino
1•modinfo•27m ago•0 comments

A Cyanometer and a Cloud Colourimeter

https://byopiapress.wordpress.com/2024/05/19/a-cyanometer-and-a-cloud-colourimeter/
1•Kaibeezy•28m ago•0 comments

Anthropic tells investors annualized revenue run rate climbed to $65B in July

https://www.cnbc.com/2026/08/17/anthropic-says-annualized-revenue-climbed-to-65-billion-in-july.html
2•mgh2•30m ago•1 comments

Infinite Slop

https://infiniteslop.ai/
1•mellosouls•33m ago•1 comments

12TB Steam leak exposes old game builds from 2003 to 2013

https://videocardz.com/newz/12tb-steam-leak-exposes-old-game-builds-from-2003-to-2013
1•Tiberium•33m ago•0 comments

Plainqr: A QR generator as one self-contained file, no tracking

https://raw.githack.com/EltonCherrington/plainqr/main/plainqr.html
1•memctlagent2026•38m ago•0 comments

Brits would quite like their private messages to stay private

https://www.theregister.com/security/2026/08/30/turns-out-brits-would-quite-like-their-private-me...
29•defrost•42m ago•7 comments

Inside the Goodyear Blimp: Everything You Wanted to Know [video]

https://www.youtube.com/watch?v=wQn95Ojw8hM
1•skibz•44m ago•0 comments

Garfield Gets Existential (2019)

https://www.reddit.com/r/comicstriphistory/comments/bai1js/garfield_gets_existential_that_time_in...
1•robin_reala•48m ago•0 comments

The Future of Custom Software in Enterprise

https://www.xclick-ltd.com/blog/future-of-software
1•Bolice•49m ago•0 comments

LLM Usage in Debian: General Resolution Results

https://www.debian.org/vote/2026/vote_002#outcome
2•s20n•54m ago•0 comments

Faster, higher, funnier: what we learned from China's robot games

https://www.theguardian.com/news/ng-interactive/2026/aug/29/hilarity-unease-and-relief-games-show...
1•sbulaev•1h ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.