frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

An update on upki

https://discourse.ubuntu.com/t/an-update-on-upki/77063
1•pabs3•1m ago•0 comments

Google trying to recover footage from other Guthrie home cameras

https://www.youtube.com/watch?v=658FsUNHZ0Q
1•busymom0•8m ago•1 comments

Way to Understand the Irish Economy

https://stephenkinsella.substack.com/p/the-best-way-to-understand-the-irish
1•paulpauper•12m ago•0 comments

Mature Cultural Desire

https://www.overcomingbias.com/p/mature-cultural-desire
1•paulpauper•12m ago•0 comments

Technology has changed the world in my lifetime

https://www.noahpinion.blog/p/how-technology-has-already-changed
1•paulpauper•13m ago•0 comments

Evolution of Computers [video]

https://www.youtube.com/watch?v=aa6YISbAJEA
1•measurablefunc•14m ago•0 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
1•thanthtet•14m ago•0 comments

Show HN: AI pentester – verified exploits, $999/assessment

1•gauravbsinghal•14m ago•1 comments

PEP 814 – Add frozendict built-in type

https://peps.python.org/pep-0814/
2•azhenley•16m ago•0 comments

Show HN: Rot – Financial Intelligence MCP Server

https://web-production-71423.up.railway.app/mcp-server
2•Shmungus•16m ago•0 comments

Unauthorized Immigration Effects on Local Labor Markets

https://www.frbsf.org/research-and-insights/publications/economic-letter/2026/02/unauthorized-imm...
4•johntfella•18m ago•1 comments

ChatGPT promised to help her find her soulmate. Then it betrayed her

https://www.npr.org/2026/02/14/nx-s1-5711441/ai-chatgpt-openai-love-betrayal-delusion-chatbot
1•andsoitis•18m ago•0 comments

A fluid can store solar energy and then release it as heat months later

https://arstechnica.com/science/2026/02/dna-inspired-molecule-breaks-records-for-storing-solar-heat/
3•apparent•18m ago•0 comments

GLM-5 Technical Report

https://arxiv.org/abs/2602.15763
1•meetpateltech•22m ago•0 comments

Learning Low-Level Computing and C++ by Making a Game Boy Emulator

https://byteofmelon.com/blog/2026/making-of-gamebyte
2•PaulHoule•24m ago•0 comments

I Built a Roguelike RPG Card Game with Compose Multiplatform

https://medium.com/@cliffrob25/how-i-built-a-roguelike-rpg-with-compose-multiplatform-and-skipped...
1•farmerbb•26m ago•0 comments

Show HN: I built yawdl a tiny language that compiles in the browser

https://chersbobers.github.io/posts/yawdl
1•chersbobers•27m ago•0 comments

"Vendoring" is a vile anti-pattern (2014)

https://gist.github.com/datagrok/8577287
1•todsacerdoti•27m ago•1 comments

BGP in 2025 – Geoff Huston [video]

https://www.youtube.com/watch?v=Sm1HjdmoeeA
1•Unearned5161•29m ago•0 comments

Peter Thiel knows about the AntiChrist

1•zerosizedweasle•31m ago•1 comments

Charting market dynamics in India's underground ticket resale WhatsApp groups

https://aftereod.substack.com/p/stress-fractures-indias-concert-boom
1•huwsername•33m ago•0 comments

Claimcheck: Narrowing the Gap Between Proof and Intent

https://midspiral.com/blog/claimcheck-narrowing-the-gap-between-proof-and-intent/
3•todsacerdoti•35m ago•0 comments

Show HN: Instrumental Model from Scratch (With Demo)

https://instr.io/?view=model
1•day6•37m ago•0 comments

Personal Agents with David Singleton and Hugo Barra [video]

https://www.youtube.com/watch?v=1tK_x_vxGWs
1•jairojair•40m ago•0 comments

Microsoft tests Researcher and Analyst agents in Copilot

https://www.testingcatalog.com/microsoft-tests-researcher-and-analyst-agents-in-copilot-tasks/
1•gmays•41m ago•0 comments

Show HN: Agent Audit Kit v0.1 – deterministic replay + stress for LLM agents

https://github.com/helpfuldolphin/AgentAuditKit/releases/tag/aak-v0.1.0-e3
1•helpfuldolphin•43m ago•0 comments

Honey bees navigate more precisely than previously thought

https://uni-freiburg.de/en/honey-bees-navigate-more-precisely-than-previously-thought/
4•geox•49m ago•0 comments

FBI, St. Paul police probing ICE arrest that resulted in skull fractures

https://apnews.com/article/immigration-enforcement-minneapolis-hospital-ice-beating-assault-eb305...
6•petethomas•50m ago•0 comments

Lessons learned from `oapi-codegen`'s time in the GitHub Secure Open Source Fund

https://www.jvt.me/posts/2026/02/17/oapi-codegen-github-secure/
1•zdw•55m ago•0 comments

"Observability Engineering": a book so nice, we wrote it twice

https://substack.com/home/post/p-186798752
3•donutshop•57m ago•0 comments