frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Shinjuku Station ThreeJS Model

https://satoshi7190.github.io/Shinjuku-indoor-threejs-demo/
1•Gecko4072•2m ago•0 comments

Tasty

https://www.quarter--mile.com/tasty
2•surprisetalk•5m ago•0 comments

Jacobian conjecture is false (with help of Fable)

https://twitter.com/__alpoge__/status/2079028340955197566
3•k2xl•7m ago•0 comments

Comprehensive JVM Primitive Hashtable Benchmarks

https://sooniln.github.io/posts/hashmap-benchmarks-2026/
2•tooilln•9m ago•0 comments

A deep dive into my Forgejo setup

https://a.l3x.in/blog/welcome-to-my-forge/
3•alexfortin•10m ago•1 comments

Define less, check more: Pyrefly now supports attrs

https://pyrefly.org/blog/pyrefly-attrs/
2•ocamoss•17m ago•0 comments

Hacker wipes Romania's land registry database

https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database/
8•speckx•17m ago•0 comments

The age of token efficiency, the age of libraries

https://golemui.com/blog/the-age-of-token-efficiency/
2•wtfdeveloper•18m ago•0 comments

Show HN: A 16-control subtractive synth for microcontrollers (39k ELF, web demo)

https://mini000.itch.io/beeper
2•isitcontent•20m ago•0 comments

Modder Makes GTA: Vice City Playable Inside GTA 3 Inside GTA: San Andreas

https://kotaku.com/gta-vice-city-made-playable-in-gta-3-made-playable-in-gta-san-andreas-2000717510
2•sam_anthony•22m ago•0 comments

Show HN: QUBE Predict – A cloud platform for drug response prediction

https://qube-predict.streamlit.app/
2•gfam999•24m ago•0 comments

10x and 100x increase in CPU core and node bandwidth, respectively over 20 yrs

https://ieeexplore.ieee.org/document/11196478
2•teleforce•24m ago•0 comments

Self-Service Ransomware as Security Against Local AI Tools

https://blog.brendankeaton.com/self-service-ransomware-as-security-against-local-ai-tools
2•BrKeaton•25m ago•1 comments

Languages That Stretch Your DI Capabilities and Imagination

https://programmingsimplicity.substack.com/p/languages-that-stretch-your-di-capabilities
2•surprisetalk•25m ago•0 comments

Simple Invoices. Faster Payments

https://duely-44998.bubbleapps.io/
3•03Leena03•29m ago•1 comments

Apple should let us schedule work-hours notifications for specific apps

3•hellowastaken•31m ago•3 comments

What if your AI agent could have its own WhatsApp number?

https://tyxter.com/
2•thiagocarboni•33m ago•4 comments

I predicted all WC2026 matches with Poisson Dixon-Coles – 64% accuracy

https://predictive-model.com
2•dosores•33m ago•0 comments

Underwater Kites Harvest Power from Slow-Moving Tides

https://spectrum.ieee.org/tidal-energy-underwater-kite-power
2•speckx•34m ago•1 comments

Inertia-1: An Open Exploration to a Unified Motion Foundation Model

https://yang-ai-lab.github.io/Inertia-1/
3•hasheddan•34m ago•0 comments

Association of sedentary behaviors w cortical, subcortical &white matter volumes

https://alz-journals.onlinelibrary.wiley.com/doi/10.1002/alz.71582
2•bookofjoe•38m ago•0 comments

Where B2B Buyers Ask on Reddit: 30 Days of Scan Data

https://cuescout.com/blog/where-b2b-buyers-actually-ask-on-reddit
3•tgdaimov•38m ago•0 comments

The asymmetry problem: AI safeguards are mainly annoying to the good guys

https://cephalosec.com/blog/the-asymmetry-problem-ai-safeguards-are-mostly-hindering-the-good-guys/
2•Versipelle•38m ago•0 comments

We're Squandering LEDs' Potential to Save Our Night Skies

https://spectrum.ieee.org/led-light-pollution
2•defrost•38m ago•0 comments

Landmark Science Report Confirms Big Oil's Fingerprints on Extreme Weather

https://www.commondreams.org/newswire/landmark-science-report-confirms-big-oils-fingerprints-on-e...
2•robtherobber•39m ago•0 comments

Codex is wearing out our devices

https://old.reddit.com/r/codex/comments/1v0m3lt/codex_is_wearing_out_our_devices/
4•spenvo•41m ago•2 comments

Grading Is Easy, Feedback Is Hard: Evaluating LLMs for OOP Assessment [pdf]

https://github.com/elipcs/grading-is-easy-feedback-is-hard/blob/main/docs/Grading_Is_Easy_Feedbac...
2•lucis•43m ago•0 comments

Memory Safety's Hardest Problem

https://matklad.github.io/2026/07/20/memory-safety-hardest-problem.html
2•surprisetalk•43m ago•0 comments

Show HN: Give your AI agent a personality (and a voice) without external APIs

https://fellowgeek.github.io/mcp-speak/
2•pcbmaker20•44m ago•0 comments

AgentBaiting: Fake AI Skills and MCP Servers Delivered Malware

https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware
2•deronEx•44m ago•0 comments