frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

I Tried to Invent a Better Replication Policy. It Failed

https://halil.cetiner.me/nearsight/
1•bayneri•48s ago•0 comments

A Eulogy for Vim

https://drewdevault.com/2026/03/25/2026-03-25-Forking-vim.html
1•mtts•2m ago•0 comments

TeamMind – persistent memory for Claude Code (no API key, runs locally)

https://github.com/natedemoss/Teammind
1•natedemoss•2m ago•0 comments

The Cost of Doing Business

https://pluralistic.net/2026/03/25/fact-intensive/
1•hn_acker•2m ago•0 comments

Show HN: Marco, a privacy-first, offline-first email client (IMAP-native, no AI)

https://marcoapp.io/
1•isaachinman•2m ago•0 comments

A 500K-parameter system that recovers invariant physics from observation alone

https://erebus.org/
1•ordinarily•2m ago•0 comments

Quantization from the Ground Up

https://ngrok.com/blog/quantization
1•samwho•2m ago•0 comments

Dan rewrote chardet, relicensed to MIT. Original author broke 15-year silence

https://www.elvex.com/podcast/he-rewrote-chardet-with-claude-the-internet-blew-up-heres-his-take
3•sak84•3m ago•0 comments

Show HN: Dbt-skillz compiles your dbt project into a Claude Code skill

https://github.com/atlasfutures/dbt-skillz
2•davidvgilmore•3m ago•0 comments

Lyria 3 Pro: Create longer tracks in more Google products

https://blog.google/innovation-and-ai/technology/ai/lyria-3-pro/
1•meetpateltech•4m ago•0 comments

Closing the knowledge gap with agent skills

https://developers.googleblog.com/closing-the-knowledge-gap-with-agent-skills/
1•xnx•4m ago•0 comments

RSA and Python

https://xnacly.me/posts/2023/rsa/
1•ibobev•4m ago•0 comments

Installing PyTorch with AMD ROCm on GNU/Linux

https://www.wedesoft.de/graphics/2026/03/24/rocm-torch-install/
1•ibobev•5m ago•0 comments

GitHub Nukes 900 Anime Piracy Repos and Forks, but Rejects Circumvention Claims

https://torrentfreak.com/github-nukes-900-anime-piracy-repos-and-forks-but-rejects-circumvention-...
1•t-3•6m ago•0 comments

Ask HN: Will juniors still learn coding the hard way?

1•QubridAI•6m ago•0 comments

Writing an LLM from scratch, part 32g – Interventions: weight tying

https://www.gilesthomas.com/2026/03/llm-from-scratch-32g-interventions-weight-tying
1•ibobev•6m ago•0 comments

Introducing DDD to Your Organization

https://docs.eventsourcingdb.io/blog/2026/03/26/introducing-ddd-to-your-organization/
1•goloroden•7m ago•0 comments

In Math, Rigor Is Vital. But Are Digitized Proofs Taking It Too Far?

https://www.quantamagazine.org/in-math-rigor-is-vital-but-are-digitized-proofs-taking-it-too-far-...
1•tzury•8m ago•0 comments

Prediction trading is coming to Canada

https://www.theglobeandmail.com/business/article-wealthsimple-clears-regulatory-hurdle-to-bring-p...
1•jprs•8m ago•1 comments

I Am the Bottleneck

https://www.bretmorgan.me/writing/2026/03/24/i-am-the-bottleneck/
1•strooltz•8m ago•0 comments

New American dream may come with a broker, a balance sheet and now an AI copilot

https://refreshmiami.com/news/the-new-american-dream-may-come-with-a-broker-a-balance-sheet-and-n...
1•lifenautjoe•8m ago•0 comments

The demise of public key encryption will come sooner than thought, Google warns

https://arstechnica.com/security/2026/03/google-bumps-up-q-day-estimate-to-2029-far-sooner-than-p...
1•ooboe•9m ago•1 comments

UK teenagers to trial six-week social media curbs for major study

https://www.theguardian.com/uk-news/2026/mar/25/hundreds-of-uk-teenagers-to-trial-six-week-social...
1•chrisjj•9m ago•0 comments

Should a conscious AI be given Human rights?

1•PalantirDroned•9m ago•0 comments

Miracle – old school cool [video]

https://www.youtube.com/watch?v=EVFmVPWKv4c
1•marysminefnuf•9m ago•0 comments

Mini Brains Just Learned to Solve a Classic Engineering Problem

https://singularityhub.com/2026/03/24/these-mini-brains-just-learned-to-solve-a-classic-engineeri...
1•Brajeshwar•10m ago•0 comments

Death by Clawd

https://deathbyclawd.com
1•speter•12m ago•0 comments

Google's extreme AI compression paper was on arXiv since April 2025

https://arxiv.org/abs/2504.19874
1•fadijob•13m ago•1 comments

The Dual State: A Contribution to the Theory of Dictatorship (1941, Pdf)

https://ia601502.us.archive.org/26/items/in.ernet.dli.2015.13142/2015.13142.The-Dual-State.pdf
1•burnt-resistor•13m ago•1 comments

Ubuntu 26.10 Looks to Strip Its Grub Bootloader to the Bare Minimum for Security

https://www.phoronix.com/news/Ubuntu-26.10-Lighter-GRUB
1•josephcsible•14m ago•1 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•10mo ago

Comments

kemotep•10mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.