frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Hyperbolic Version of Napier's Mnemonic

https://www.johndcook.com/blog/2026/04/02/hyperbolic-napier-mnemonic/
1•ibobev•14s ago•0 comments

Earthset and a solar eclipse: NASA releases first images from Moon fly-by

https://www.bbc.com/news/articles/cyv183v02j3o
1•meetpateltech•27s ago•0 comments

The Golden Path to Chaos: Adiabatic Twists

https://galileo-unbound.blog/2026/04/07/the-golden-path-to-chaos-adiabatic-twists/
1•ibobev•40s ago•0 comments

Decentralized Training Can Help Solve AI's Energy Woes

https://spectrum.ieee.org/decentralized-ai-training-2676670858
1•pseudolus•43s ago•0 comments

Anyone can code with AI. But it might come with a hidden cost

https://www.nbcnews.com/tech/security/ai-code-vibe-claude-openai-chatgpt-rcna258807
1•Kerrick•44s ago•0 comments

Why AI Systems Fail Quietly

https://spectrum.ieee.org/ai-reliability
2•Brajeshwar•1m ago•0 comments

Only 28% of AI infrastructure projects pay off, survey finds

https://www.theregister.com/2026/04/07/ai_returns_gartner/
1•Brajeshwar•1m ago•0 comments

Why Your Automated Pentesting Tool Just Hit a Wall

https://www.bleepingcomputer.com/news/security/why-your-automated-pentesting-tool-just-hit-a-wall/
1•Brajeshwar•1m ago•0 comments

Show HN: 85ns latency on a $100 Android device using Rust

1•Aegis_Labs•1m ago•0 comments

Are You Managing Your AI, or Is Your AI Managing You?

https://octigen.com/blog/posts/2026-04-07-whos-boss/
2•m_mueller•2m ago•0 comments

Build, edit, and analyze forms directly inside ChatGPT

https://www.jotform.com/chatgpt/
1•aytekin•2m ago•1 comments

Tesla won't build its own chip fab – Intel is going to do it

https://electrek.co/2026/04/07/tesla-terafab-intel-joins-foundry/
1•breve•2m ago•0 comments

Principles of Mechanical Sympathy

https://martinfowler.com/articles/mechanical-sympathy-principles.html
1•zdw•4m ago•0 comments

Trial by Fire: Crisis Engineering

https://www.eatingpolicy.com/p/trial-by-fire-crisis-engineering
1•brandonb•5m ago•0 comments

WASM Interpreter Transformer

https://huggingface.co/eastlondoner/wasm-interpreter-transformer
1•ozb•5m ago•0 comments

Show HN: The King James Bible deserved a better website

https://officialkingjamesbible.com/
1•L23234•5m ago•0 comments

Show HN: Brighten Up – My First App. Lessons on Unity and Renting a Mac

https://apps.apple.com/us/app/brighten-up/id6759843847
1•Dan1435•6m ago•1 comments

Shader-driven web transitions with HTML-in-canvas

https://github.com/MaxLeiter/compiz-web/
1•MaxLeiter•6m ago•1 comments

DNS configuration tampering on a pool.ntp.org GeoDNS server

https://community.ntppool.org/t/dns-configuration-tampering-on-one-of-our-geodns-servers/4300
1•j03b•6m ago•0 comments

Nobody Talks About the Hardware

https://jordivillar.com/notes/nobody-talks-about-the-hardware
2•speckx•6m ago•0 comments

Indxr v0.4.0 – Teach your agents to learn from their mistakes

https://github.com/bahdotsh/indxr
1•bahdotshxx•7m ago•0 comments

What historical evidence do we have of Jesus' crucifixion and its aftermath

https://old.reddit.com/r/AskHistorians/comments/1se0vrh/what_historical_evidence_do_we_have_of_je...
1•andrepd•7m ago•0 comments

The UI of Agentic SaaS

https://akashyap.ai/the-ui-of-agentic-saas/
2•KashyapArjun•7m ago•0 comments

Show HN: JavaScript runtime instrumentation via Chrome DevTools Protocol

https://fcavallarin.github.io/wirebrowser/CDP-as-a-Runtime-Instrumentation-Engine.html
1•fcavallarin•8m ago•0 comments

Show HN: BitBang – P2P tunnels to localhost, no account required

https://github.com/richlegrand/bitbang
1•narragansett•8m ago•0 comments

Show HN: SolidUptime – Uptime monitoring with incident grouping (free, no CC)

https://soliduptime.org/
2•Abs46•9m ago•1 comments

Vairav Fintech Threat Index

https://mailchi.mp/7ad331ac5d91/fintech-threat-index-q1-2026
1•cyberdefender•9m ago•0 comments

Antarctica, and the Extreme Logistics of Human Exploration

https://www.a16z.news/p/antarctica-and-the-extreme-logistics
1•7777777phil•10m ago•0 comments

Cloudflare targets 2029 for full post-quantum security

https://blog.cloudflare.com/post-quantum-roadmap/
2•ilreb•11m ago•0 comments

Show HN: RBF-Attention – Trading dot-products for Euclidean distance

https://www.pisoni.ai/posts/scaled-rbf-attention/
1•4rtemi5•11m ago•1 comments