frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Syria, eyeing role as Middle East hub, offers options to bypass Hormuz

https://www.washingtonpost.com/world/2026/09/02/syria-eyeing-role-middle-east-hub-offers-options-...
1•divbzero•1m ago•0 comments

Show HN: Mitmcloak – mirror the client's TLS/H2/H3 fingerprint in mitmproxy

https://github.com/sardanioss/mitmcloak
1•sardanios•2m ago•0 comments

John Ternus Is Now Apple CEO

https://www.macrumors.com/2026/09/01/john-ternus-first-memo/
1•signa11•3m ago•0 comments

Trees use a "muscle", tension wood, to correct their posture

https://phys.org/news/2026-09-trees-muscle-posture-newly-role.html
1•mdp2021•4m ago•0 comments

From Rg to Zg: Local Search Beyond Keywords

https://zvec.org/en/blog/2026-08-28-zvec-grep-open-source/
2•fang2hou•7m ago•0 comments

Statutory Copyleft

https://www.thomas-huehn.com/statutory-copyleft/
2•Tomte•9m ago•0 comments

Tech Pilgrims Flock to China

https://www.reuters.com/world/china/tech-pilgrims-flock-china-global-innovation-race-heats-up-202...
3•TechTechTech•9m ago•0 comments

Brave for Desktop Outperforms Other Browsers in Speed and Performance

https://brave.com/blog/brave-outperforms-other-browsers/
3•crbelaus•11m ago•0 comments

Germany on track for strongest GDP growth since 2022

https://www.ft.com/content/6b396499-d71d-4e8f-b2a4-66318b1d9426
3•mertbio•12m ago•1 comments

Outdoor displays fail in places you don't expect

https://duobond-display.com/news/display-interfaces-system-integration/532.html
2•Todorov•13m ago•0 comments

Hackers Don't Break in Anymore, They Log In

https://redmondmag.com/articles/2026/03/10/hackers-dont-break-in-anymore.aspx
3•janandonly•14m ago•0 comments

Show HN: Shri-io – a privacy-first, self-hosted URL shortener

https://github.com/barats/shrl-io
2•baratsemet•15m ago•0 comments

AI and the collapse of the intelligence-based hierarchy of merit

https://mattbruenig.com/2026/08/31/more-thoughts-on-ai/
3•rzk•20m ago•0 comments

Do you code in silence or do you listen to music?

https://textlog.cc/post/1078
3•stagas•20m ago•0 comments

Reticulum Is Not a Democracy

3•supernihil•23m ago•0 comments

Code Review Is Dead?

https://gioorgi.com/2026/code-review-dead/
2•daitangio•23m ago•1 comments

False Completion Is the Real Failure Mode of Coding Agents

https://medium.com/@giladha/false-completion-is-the-real-failure-mode-of-coding-agents-744be5a8c9c4
2•giladha•25m ago•0 comments

Apple Speech vs. Whisper: How Good Is Apple's New SpeechAnalyzer?

https://whispernotes.app/blog/apple-speech-vs-whisper
1•mazzystar•26m ago•0 comments

AI agents carried out every step of this ransomware attack – then left

https://www.theregister.com/security/2026/09/02/ai-agents-carried-out-every-step-of-this-ransomwa...
2•sbulaev•27m ago•0 comments

Why Ilya Sutskever's $32B SSI Valuation Highlights a Fatal Epistemic Vacuum

https://zenodo.org/records/22162749
1•AaRubinstein_CA•28m ago•0 comments

Three schoolgirls in Kinsale pulled up a pea plant covered in warts

https://scienceblog.com/b-three-schoolgirls-in-kinsale-pulled-up-a-pea-plant-covered-in-warts-and...
3•DamonHD•30m ago•1 comments

The Download: AI puzzles and a path to our nearest star system

https://www.technologyreview.com/2026/09/02/1143283/the-download-ai-puzzles-alpha-centauri-mission/
1•joozio•31m ago•0 comments

Sandbox

2•cyteeditor•32m ago•0 comments

Chat Bots Compared: An interactive quiz to find AI companions

https://chatbotscompared.com/
1•Sharanxxxx•32m ago•0 comments

Pre-Release of Polars 2.0

https://pola.rs/posts/announcing-polars-2/
2•komape•35m ago•0 comments

The birthday paradox and why hashes are 256 bits, not 128

https://sslog.dpdns.org/birthday-attack.html
1•Shaurya_Sharma•38m ago•0 comments

An open-source design plugin that helps your AI build less generic websites

https://github.com/MickeyAlton33/web-designer-plugin
1•Nina_antalpha•41m ago•0 comments

Sex After AGI

https://twitter.com/Joshbocanegra/status/2093122061116035105
1•jbai•43m ago•0 comments

Terence Tao: Protecting math problems from automated solvers

https://mathstodon.xyz/@tao/117204929023813310
4•bertman•43m ago•0 comments

No Vibe Coding: Discussion Coding on Termux – Phone Only, Zero Trust

https://m.blog.naver.com/amadale/224399795090
1•garlicfarmer•46m ago•0 comments