frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Scientists explain how a 300 TeV photon could reach Earth

https://physicsworld.com/a/scientists-explain-how-a-300-tev-photon-could-reach-earth/
1•EA-3167•1m ago•0 comments

Agent-harness – A minimal, composable Go library to build AI Agent Harnesses

https://github.com/lox/agent-harness
1•peter_d_sherman•2m ago•0 comments

Canadian-German AI lab eyes building sovereign AI for Europe

https://www.rapporteur.com/news/canadian-german-ai-lab-eyes-building-efficient-and-sovereign-ai-f...
1•doener•3m ago•0 comments

Fast Blur with Animated Radius

https://aras-p.info/blog/2026/10/01/Fast-blur-with-animated-radius/
1•luu•4m ago•0 comments

Counter Intelligence Invitation

https://www.meetup.com/counter/events/316808135/
2•shoman3003•7m ago•0 comments

Creatine may help build muscle even without exercise, researchers find

https://www.sciencedaily.com/releases/2026/09/260928100547.htm
2•gradus_ad•12m ago•0 comments

Non-Devs Just Don't Understand

https://joecmarshall.com/posts/non-devs-just-dont-understand/
2•webappsecperson•14m ago•0 comments

ArXiv updates its rate limiting policy

https://terrytao.wordpress.com/2026/10/01/arxiv-updates-its-rate-limiting-policy/
1•smilelamp•17m ago•0 comments

Better Call GPT – Plugin for Talking to Claude Code in Live

https://github.com/insta-fusion/bettercallgpt
1•instafusion•19m ago•0 comments

Grok reportedly encouraged the capture of Venezuela's president

https://techcrunch.com/2026/10/01/musks-ai-chatbot-grok-reportedly-encouraged-trump-to-capture-ve...
1•OutOfHere•22m ago•0 comments

CHM Live – Anthropic's Boris Cherny, Creator of Claude Code [video]

https://www.youtube.com/watch?v=djDt8J2_YVs
1•elkguy•22m ago•0 comments

Braxis: Auto-generate and track AI agent readiness (0-100 score and history)

https://github.com/jaykrishna316/braxis
1•Jaykrishna316•22m ago•0 comments

The AI industry is a complete mess [video]

https://www.youtube.com/watch?v=e2zjpCqTmyo
2•miletus•25m ago•0 comments

At Work, AI Is Mandatory. After Work, It's Forbidden

https://medium.com/@yalovoy/at-work-ai-is-mandatory-after-work-its-forbidden-d12bbd78851c
2•zero-ground-445•27m ago•0 comments

Pentagon Creates 'Autowarcom' to Expand AI and Drone Capabilities

https://www.reuters.com/world/pentagon-creates-autowarcom-expand-ai-drone-capabilities-2026-09-30/
1•m463•28m ago•0 comments

Show HN: Visi – Excel as a CLI

https://github.com/albert-yu/visi
1•albert-yu•29m ago•0 comments

Maylang – A self-hosted systems language compiled with LLMs

https://github.com/mirged/maylang
1•mirged•38m ago•1 comments

OpenAI fires three workers over mishandling 'sensitive information'

https://www.bbc.com/news/articles/c6y9z9r4ejzwo
6•geox•39m ago•0 comments

Best-of-Agent-Harnesses – Ranked list of 167 AI agent harnesses, rescored weekly

https://github.com/ryanalberts/best-of-agent-harnesses
4•peter_d_sherman•40m ago•0 comments

How Singapore's government-run dating service works

https://www.singapore-samizdat.com/p/how-singapores-government-run-dating-service-firstdate-works
2•danielfoster•41m ago•0 comments

Show HN: Simply @dotlink in ChatGPT web,space or dot to access local files,tools

https://github.com/abird-ai/dotlink/
1•logxroot•43m ago•0 comments

Pentagon launches Office of Religious Affairs, will report directly to Hegseth

https://www.militarytimes.com/news/pentagon-congress/2026/10/01/pentagon-launches-office-of-relig...
4•embedding-shape•43m ago•1 comments

Show HN: A userspace only nwing client for Tailscale nw

https://github.com/krishnakumar4a4/tail-userspace
1•krishnakumar4a4•46m ago•0 comments

Pg_redact: Content-aware PII redaction with Jev, enforced in Postgres

https://neon.com/blog/pg-redact-content-aware-pii-redaction-with-jev-enforced-in-postgres
1•thruflo22•49m ago•0 comments

Someone Torturing LLMs in a Robot Prison Has Triggered the Dumbest Debate in AI

https://www.404media.co/someone-torturing-llms-in-a-robot-prison-has-triggered-the-dumbest-debate...
2•Refreeze5224•55m ago•0 comments

Exhaling may speed up reaction times

https://www.sciencenews.org/article/reaction-times-sync-breathing-brain
2•wawayanda•1h ago•1 comments

Can your Postgres survive a bad query?

https://clickhouse.com/blog/can-your-postgres-survive-a-bad-query
2•saisrirampur•1h ago•0 comments

Luainstaller: "Pyinstaller" for Lua [video]

https://www.youtube.com/watch?v=ctYfIRZeuYc
1•linzhangrun•1h ago•0 comments

CIRCT – An experimental effort to apply MLIR and LLVM to hardware design tools

https://circt.llvm.org
1•peter_d_sherman•1h ago•0 comments

Apex: Agentic coding for mobile and web, fluent in React

https://apex.callstack.com/
1•handfuloflight•1h ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.