frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

You Were Tricked: An 8000 Word Response to Lars Lofgren's Viral Codesmith Piece

https://michaelnovati.substack.com/p/a-response-to-lars-lofgrens-codesmith
1•michaelnovati•59s ago•1 comments

29th August 2026: A Scenario

https://martinalderson.com/posts/august-29-2026-a-scenario/
1•martinald•1m ago•0 comments

Automatically switch Android's dark mode using ambient light sensor

https://www.howtogeek.com/i-ditched-sunrisesunset-dark-mode-for-this-android-app-it-uses-your-lig...
1•politelemon•1m ago•0 comments

Show HN: KIP Pattern – A React architecture pattern for true encapsulation

https://github.com/Miladxsar23/kip-pattern
1•milad_shirian•2m ago•0 comments

Send Large Files Online – Free, Secure and Unlimited

https://fromsmash.com/
1•janandonly•4m ago•0 comments

How HN: BibCrit – LLM analysis grounded in real manuscript corpus data

https://bibcrit.app/
1•jossifresben•8m ago•1 comments

More than half of pilots have fallen asleep while in charge of a plane (2013)

https://www.bbc.com/news/uk-24296544
2•johnbarron•10m ago•1 comments

Flipper: Beautiful, performant feature flags for Ruby

https://github.com/flippercloud/flipper
1•thunderbong•11m ago•0 comments

Analyzing the Patterns of Numbers in 10M Passwords (2015)

https://minimaxir.com/2015/02/password-numbers/
1•downbad_•14m ago•1 comments

Show HN: Looq, the capabilities macOS Quick Look should have shipped with

https://parcse.com/looq
2•parcse•14m ago•0 comments

Show HN: Capsule Bash – Sandboxed Bash for Agents

https://github.com/capsulerun/bash
1•mavdol04•14m ago•1 comments

Pomiferous: The most extensive apples (pommes) database

https://pomiferous.com/
1•Ariarule•16m ago•0 comments

How citations ruined science

https://davidoks.blog/p/how-citations-ruined-science
1•jprs•18m ago•0 comments

Are closed social networks inevitable? (2010)

https://danluu.com/open-social-networks/
2•downbad_•19m ago•1 comments

Knowledge Infra for Agents and Humans

https://dosu.dev
1•devstein•19m ago•0 comments

LandingRank – community-ranked landing page directory with daily Elo battles

https://landingrank.com
1•_FakeBanana_•19m ago•0 comments

Systems Are Visual – This Is a Better Way to Write Them

https://toolkit.whysonil.dev/lab-notebook/
3•otterwilde2•22m ago•0 comments

Vitexec – allow agents to test Vite apps through injected code

https://www.youtube.com/watch?v=yhIOSjp6pqs
1•BelaBohlender•22m ago•0 comments

They Left Receipts: Inside Charming Kitten's Crypto Procurement Network

https://caudena.com/charming-kitten-crypto-procurement-network/
2•caudena•24m ago•0 comments

8 in 10 Chatbots Inclined to Assist Users in Planning Attacks

https://www.statista.com/chart/36156/instances-where-chatbots-assisted-users-plan-a-violent-attack/
2•laurex•24m ago•0 comments

AI evals are becoming the new compute bottleneck

https://huggingface.co/blog/evaleval/eval-costs-bottleneck
3•gmays•26m ago•0 comments

Tera – System for structuring and testing complex ideas

https://github.com/Yggdrasilcsui/TERA/discussions/1�
2•Yggdrasilcsui•29m ago•0 comments

Ask HN: What's your favorite tech talk?

1•downbad_•30m ago•3 comments

Are you just an .md file?

https://deathbyclawd.com
1•laurex•30m ago•0 comments

When 'if' slows you down, avoid it

https://easylang.online/blog/branchless
1•birdculture•31m ago•0 comments

Cisco Announces End of Life for Smartlook

https://www.uxwizz.com/blog/smartlook-shutting-down
1•XCSme•31m ago•1 comments

Codex pets now work in Claude Code

https://github.com/danielkempe/clawdex
1•danielkempe•31m ago•1 comments

Computer Science, Software Engineering, and Vibe Coding

https://compsciforvibing.substack.com/p/computer-science-software-engineering
1•ingve•32m ago•0 comments

Poll: Midterms' new big players pushing agendas that voters don't support

https://www.politico.com/news/2026/05/03/poll-ai-crypto-super-pacs-voter-skepticism-midterms-0090...
2•1vuio0pswjnm7•32m ago•0 comments

Need Some Testers

2•kvthweatt•33m ago•2 comments