frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•10mo ago

Comments

kemotep•10mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Ask HN: What was it like for programmers when spreadsheets became ubiquitous?

1•yodaiken•2m ago•0 comments

Is this real? Susceptibility to deepfakes in machines and humans

https://link.springer.com/article/10.1186/s41235-025-00700-y
1•PaulHoule•2m ago•0 comments

The Price of College [video]

https://www.youtube.com/watch?v=qiAZd_Ut9sg
1•gmays•2m ago•0 comments

Reddit Post 3

https://old.reddit.com/r/PisequaltoNP/comments/1rtu4j5/solving_monotone_sat_in_om_log_n_via_binary/
1•KaoruAK•3m ago•0 comments

Kalverion Bot Overdraft Stopper new release

https://github.com/bisbeebucky/ai-bot/
1•aajjwww•4m ago•1 comments

Expanding Ecosystems (Michigan)

https://midwesthumble.substack.com/p/expanding-ecosystems
1•rmason•5m ago•0 comments

Please don't write about AI with AI

1•Arete314159•5m ago•0 comments

The medical advice on peanut allergies flipped in a generation

https://www.cbc.ca/lite/story/9.7125919
1•colinprince•8m ago•0 comments

Microservices: Shackles on Your Feet

https://howtocenterdiv.com/beyond-the-div/microservices-shackles-on-your-feet
2•birdculture•14m ago•0 comments

Bellingcat: The Osint Gatekeepers Who Can't Secure Their Own Site

https://ringmast4r.substack.com/p/the-osint-gatekeepers-who-cant-secure
3•mostcallmeyt•18m ago•1 comments

Daily pill may cure deadly sleep disorder that affects 84M people

https://www.dailymail.co.uk/health/article-15643615/pill-cure-sleep-apnea-CPAP-breathing.html
3•Bender•18m ago•0 comments

Ask HN: How do you find collaborators?

1•voidss•19m ago•1 comments

Iran war's Qatari Helium production disruption is a blow to chipmakers like TSMC

https://finance.yahoo.com/news/iran-war-could-wreak-havoc-on-farmers-create-a-potential-bottlenec...
1•spenvo•19m ago•0 comments

Meta reportedly plans layoffs as AI costs increase

https://www.theguardian.com/technology/2026/mar/13/meta-layoffs-ai
4•saikatsg•20m ago•0 comments

Do you ship vibe coded apps with security issues?

https://usevibescore.com
1•terrythreatt•21m ago•1 comments

US told to brace for extreme weather in every single state

https://www.dailymail.co.uk/news/article-15645675/us-extreme-weather-forecast-weekend-heat-polar-...
1•Bender•21m ago•0 comments

Where Censored Words Find a Safe Haven: Inside Minecraft

https://www.nytimes.com/2026/03/11/arts/minecraft-uncensored-library-united-states.html
1•bookofjoe•24m ago•1 comments

The Washington Post Is Using Reader Data to Set Subscription Prices

https://washingtonian.com/2026/03/12/the-washington-post-is-using-reader-data-to-set-subscription...
2•kklisura•24m ago•0 comments

Postgres Is the Gateway Drug

https://viggy28.dev/article/postgres-gateway-drug/
5•vira28•25m ago•1 comments

Back End Aggregation Enables Gigawatt-Scale AI Clusters

https://engineering.fb.com/2026/02/09/data-center-engineering/building-prometheus-how-backend-agg...
1•y1n0•25m ago•0 comments

Library of Short Stories

https://www.libraryofshortstories.com/
1•debo_•26m ago•0 comments

Millennium Challenge: Iran Destroyed America in a War Game

https://nationalinterest.org/blog/reboot/millennium-challenge-iran-destroyed-america-war-game-197261
1•vrganj•26m ago•0 comments

AI Codemods for Secure-by-Default Android Apps

https://engineering.fb.com/2026/03/13/android/ai-codemods-secure-by-default-android-apps-meta-tec...
1•y1n0•26m ago•1 comments

Book: The Emerging Science of Machine Learning Benchmarks

https://mlbenchmarks.org/00-preface.html
1•jxmorris12•27m ago•0 comments

Pipechart – pipe any JSON into your terminal and get a chart, zero dependencies

https://github.com/davitotty/pipechart
1•Davitotty1•28m ago•0 comments

Show HN: An Open-Source Yoto Toy with Qwen3-TTS

https://github.com/akdeb/open-toys
2•akadeb•29m ago•1 comments

My fireside chat about agentic engineering at the Pragmatic Summit

https://simonwillison.net/2026/Mar/14/pragmatic-summit/
2•lumpa•33m ago•0 comments

My Wish for Software Engineering

https://arnoldkling.substack.com/p/my-wish-for-software-engineering
1•paulpauper•33m ago•0 comments

Claude Doubles Usage Limits During Off-Peak Hours (March 13–27, 2026)

https://support.claude.com/en/articles/14063676-claude-march-2026-usage-promotion
1•weldu•34m ago•0 comments

Glow: Render Markdown on the CLI, with Pizzazz

https://github.com/charmbracelet/glow
1•thunderbong•34m ago•0 comments