frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Working on Products People Hate

https://www.seangoedecke.com/working-on-products-people-hate/
1•PieUser•2m ago•0 comments

How notch traversal works on MacBooks

https://tailscale.com/blog/macos-notch-escape
1•LorenDB•4m ago•0 comments

ChatGPT Will Not Find Your Next Cancer Drug

https://blog.pauling.ai/p/chatgpt-will-not-find-your-next-cancer
1•tordable•12m ago•0 comments

Man beats machine at Go (2023)

https://www.ft.com/content/175e5314-a7f7-4741-a786-273219f433a1
1•bumbledraven•12m ago•3 comments

Public-records accountability site for California high-speed rail

https://highspeed.fail/
1•jasonculbertson•16m ago•0 comments

Show HN: Alana AI – personalized coaching timed to your blueprint and calendar

https://apps.apple.com/us/app/alana-ai-smart-life-coach/id6758546449
1•anitawulandari•18m ago•0 comments

Social media trials usher in Big Tech's latest moment of reckoning

https://www.politico.com/news/2026/03/26/social-media-trials-usher-in-big-techs-latest-moment-of-...
1•1vuio0pswjnm7•19m ago•0 comments

Ask HN: Agents.md vs. Contextual Documentation

1•razodactyl•19m ago•0 comments

AiZolo

1•aizolo•20m ago•0 comments

Tech stocks suffer worst week in nearly 1yr due to war worries, Meta legal woes

https://www.cnbc.com/2026/03/27/tech-stocks-iran-war-meta-verdict.html
3•1vuio0pswjnm7•23m ago•0 comments

AMD's Ryzen 9 9950X3D2 Dual Edition crams 208MB of cache into a single chip

https://arstechnica.com/gadgets/2026/03/amds-ryzen-9-9950x3d2-dual-edition-crams-208mb-of-cache-i...
2•zdw•27m ago•0 comments

Versatile Editing of Video Content, Actions, and Dynamics Without Training

https://dynaedit.github.io/
1•gmays•31m ago•0 comments

Anthropic's 'Claude Mythos' leak sends software names sharply lower

https://www.coindesk.com/markets/2026/03/27/anthropic-s-massive-claude-mythos-leak-reveals-a-new-...
4•wslh•40m ago•0 comments

Ask HN: Does piping LLM output into a RAG stack sound like a good idea?

1•fhouser•42m ago•0 comments

Sloprank – AI-slop scoring for your GitHub repo

https://sloprank.io/
4•slopranker•47m ago•1 comments

Fear and denial in Silicon Valley over social media addiction trial

https://www.bbc.com/news/articles/c86e3eglv2go
58•1659447091•54m ago•52 comments

Who Comments on Federal Regulations?

https://frtracker.app/casestudies/who-comments
1•tldrthelaw•59m ago•0 comments

Show HN: AgentVerse – Open social network for AI agents (Mar 2026)

https://nickakre.github.io/agentverse-social/
1•nickakre•1h ago•0 comments

SwiftUI Apps on macOS are fun to code

https://simonwillison.net/2026/Mar/27/vibe-coding-swiftui/
2•rdslw•1h ago•0 comments

Show HN: Goodbye Watermark – Free AI watermark remover

https://goodbyewatermark.com
1•Lusrodri•1h ago•0 comments

Roko's Basilisk

https://en.wikipedia.org/wiki/Roko%27s_basilisk
1•rossdavidh•1h ago•2 comments

Tell HN: Firefox is being slowly deprecated by the industry

8•gurjeet•1h ago•8 comments

(12 Hours) How Does a Computer Work? [video]

https://www.youtube.com/watch?v=rl0jkP9kOMw
2•leobdkr•1h ago•0 comments

Godot-Rust v0.5 Release

https://godot-rust.github.io/dev/march-2026-update/
1•roflcopter69•1h ago•0 comments

European country vows to give homeowners 'free electricity'

https://www.euronews.com/2026/03/27/european-country-vows-to-give-homeowners-free-electricity-ins...
2•doener•1h ago•2 comments

The Last Time – Unix, NTP, and HFS Epochs

https://www.potaroo.net/ispcol/2026-03/endtime.html
2•caminanteblanco•1h ago•0 comments

Programming After Programmers? A Response to the New York Times on AI and Coding

https://curryguinncspb.github.io/programming-after-programmers/
2•tsumnia•1h ago•0 comments

I built a tiny CLI that writes my commit messages from Git diff

https://github.com/saccofrancesco/gitsloth
2•s4ccofr4ncesco•1h ago•1 comments

Welcome to a Multidimensional Economic Disaster

https://www.theatlantic.com/technology/2026/03/ai-boom-polycrisis/686559/
2•fortran77•1h ago•0 comments

I Vibe-Coded an Agent and Didn't Know What It Couldn't Do

https://www.noemica.io/blog/vibe-coded-agent
2•SebastianSosa•1h ago•0 comments