frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Show HN: yawac – a macOS client for WhatsApp, Swift, no Electron, no BS

https://github.com/vadika/yawac/
1•vadikas•18s ago•0 comments

We Built a Real-Time Implied Volatility Engine for Commodity Options

https://medium.com/@DolphinDB_Inc/how-we-built-a-real-time-implied-volatility-engine-for-commodit...
1•CrazyTomato•27s ago•0 comments

The Ideal Bestest Base Font Size That Everyone Is Keeping a Secret

https://adrianroselli.com/2024/03/the-ultimate-ideal-bestest-base-font-size-that-everyone-is-keep...
1•ravenical•1m ago•0 comments

Anthropic CEO Dario Amodei Has Only One Direct Report

https://www.bloomberg.com/news/articles/2026-06-10/anthropic-ceo-dario-amodei-is-a-manager-to-onl...
1•petethomas•6m ago•0 comments

Billions in Loans Didn't Make a Dent in Global Poverty

https://www.wsj.com/finance/banking/poverty-microfinancing-loans-entrepreneurs-de458ee8
1•JumpCrisscross•8m ago•0 comments

Show HW: nomd, HTML md editor

https://nomd.dev
1•pcald•9m ago•0 comments

Web Browsers on Video Game Consoles

https://vale.rocks/posts/game-console-browsers
1•robin_reala•10m ago•0 comments

Ex-Board Member Reveals Corruption and Dysfunction at Gnome Foundation

https://lunduke.substack.com/p/ex-board-member-reveals-corruption
2•MrJulia•11m ago•0 comments

Show HN: Corterm – self-hosted remote terminal that survives disconnects

https://github.com/monster-echo/CortexTerminal2
1•rwecho•11m ago•1 comments

V2 Editor (2025)

https://oktana.dev/blog/introducing-v2-editor/
1•rapnie•11m ago•0 comments

Getting Started with Datastar – Build a Rust and Axum Todo App

https://hamy.xyz/blog/2026-03_datastar-rust-todo
1•alex_hirner•11m ago•0 comments

Our AI-slop ad turned out weirdly good [video]

https://www.youtube.com/watch?v=FPgq4eopYcs
1•nxnze•11m ago•1 comments

I made a chess leaderboard that rewards cool checkmates instead of just Elo

https://chessranks.net/
1•nashrashal•14m ago•0 comments

Tiny wasp helps prevent first global bird extinction in Britain for 60 years

https://www.rspb.org.uk/whats-happening/news/tiny-wasp-helps-prevent-the-first-global-bird-extinc...
1•austinallegro•15m ago•2 comments

OT Segmentation: Why the Framework Matters Less Than the Discipline

https://www.emberot.com/resources/blog/ot-segmentation-discipline-framework/
1•TheWiggles•15m ago•0 comments

I added a prompt to future ASI – TLBIC Policy Proposal v5 now available

1•michikawa59•17m ago•0 comments

IBM's Spyre AI Accelerator Deep Dive – By Gavin Bonshor

https://morethanmoore.substack.com/p/ibms-spyre-ai-accelerator-deep-dive
1•rbanffy•19m ago•0 comments

Making a Vintage LLM from Scratch

https://crlf.link/log/entries/260525-1/
2•croqaz•20m ago•1 comments

Collaborative Memory Chrome Extension

https://chromewebstore.google.com/detail/xysq-memory-for-you-and-y/knpcnfdnahkinongbiedcllmigffodpm
1•ximihoque•20m ago•0 comments

Unmasking the Energy Transition Myth [video]

https://www.youtube.com/watch?v=H24Xzi7Xi5I
1•leonidasrup•21m ago•1 comments

The "steroid Olympics" were a circus–and a window into our culture

https://www.technologyreview.com/2026/06/10/1138670/enhanced-games-doping-steroids-hormones-suppl...
1•joozio•24m ago•0 comments

Show HN: SynCodeLive – code and talk with your team along with AI, live

https://syncodelive.com/
1•ketul_shah•26m ago•0 comments

Agentic Coding and Mental Models

https://philbooth.me/blog/agentic-coding-and-mental-models
1•philbo•28m ago•0 comments

Framework delays Laptop 13 Pro due to bugs, but there's a bonus

https://www.pcworld.com/article/3162530/framework-delays-laptop-13-pro-due-to-bugs-but-theres-a-b...
1•cassianoleal•28m ago•0 comments

Why Sell Lifetime Plans, in a Default Subscription World?

https://pketh.org/lifetime-plans.html
1•ZacnyLos•29m ago•1 comments

Extra Time – a retro-newspaper companion for the 2026 World Cup

https://extra-time-wc2026.netlify.app
1•regevaz•32m ago•0 comments

The vulnerability bottleneck has moved

https://evahill1.substack.com/p/the-vulnerability-bottleneck-has
2•evaXhill•32m ago•0 comments

Connected Notes and Writing from Curiosity Turned a Hobby into a Career

https://www.ssp.sh/blog/why-i-still-blog/
2•zazuke•33m ago•0 comments

Unintended Consequences of Video Surveillance

https://spectrum.ieee.org/unintended-consequences-video-surveillance
1•rbanffy•38m ago•0 comments

Intelligence Not Included

https://morrick.me/archives/10319
1•jandeboevrie•38m ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.