frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Claude Code Connected to Apple Car Play and Android Auto [video]

https://www.youtube.com/shorts/edA00WNhNwM
2•johnkg003•4m ago•1 comments

Are you richer than your neighbor?

https://brokeorrich.com/
1•Mawenzi•7m ago•1 comments

Meta's Big Tobacco PR Tactics

https://yadin.com/notes/toasted/
1•dryadin•8m ago•0 comments

The AI supply crunch is here

https://www.economist.com/leaders/2026/04/30/the-ai-supply-crunch-is-here
2•pingou•8m ago•1 comments

Barbara Liskov on Dijkstra, Abstraction, Distributed Systems [video]

https://www.youtube.com/watch?v=T9CGjbPZeaM
1•tosh•13m ago•0 comments

U.S. Seizes $15B in Bitcoin in Crypto 'Scam' Crackdown

https://www.forbes.com/sites/martinacastellanos/2025/10/14/us-seizes-15-billion-in-bitcoin-sancti...
1•maxloh•14m ago•1 comments

Monopoly Concepts in Microeconomics: De Beers and Diamond Industry

https://www.studocu.com/in/document/university-of-johannesburg/microeconomic-issues-in-developmen...
1•cathrinea•14m ago•0 comments

Show HN: Kencode – Compact Kotlin serialization for URLs and labels

https://eignex.com/posts/kencode-packing-data-for-strict-limits/
2•monom•14m ago•1 comments

If I Could Make My Own GitHub

https://matduggan.com/if-i-could-make-my-own-github/
1•vinhnx•22m ago•0 comments

Apple Says Mac Studio and Mac Mini Will Be in Short Supply for Months

https://www.macrumors.com/2026/04/30/mac-studio-mac-mini-constrained-months/
9•tosh•22m ago•0 comments

A text editor as a user interface

https://ratfactor.com/cards/text-editor-as-ui
1•vinhnx•23m ago•0 comments

Sure: The personal finance app, community fork of Maybe Finance

https://github.com/we-promise/sure
1•sebakubisz•23m ago•0 comments

Surviving Black Friday: 329B requests with Falcon

https://speakerdeck.com/ioquatix/surviving-black-friday-329-billion-requests-with-falcon
2•ksec•25m ago•0 comments

Reunderstanding the Power of AI Through Reverse Engineering

https://blog.huli.tw/2026/04/18/en/ai-reverse-engineering-op/
1•swq115•29m ago•0 comments

US freezes $344M in cryptocurrency said to be linked to Iran

https://www.cnn.com/2026/04/24/politics/us-freezes-cryptocurrency-iran
3•maxloh•29m ago•0 comments

Openpi-flash: Real-time inference engine for openpi

https://github.com/Hebbian-Robotics/openpi-flash
1•kstonekuan•30m ago•0 comments

Advocacy groups issue US travel advisory ahead of World Cup

https://www.washingtonblade.com/2026/04/29/advocacy-groups-issue-us-travel-advisory-ahead-of-worl...
1•latexr•32m ago•0 comments

Andrej Karpathy: From Vibe Coding to Agentic Engineering [video]

https://www.youtube.com/watch?v=96jN2OCOfLs
1•vinhnx•37m ago•0 comments

Do birds have accents? the regional differences in birdsong

https://theconversation.com/do-birds-have-accents-the-fascinating-regional-differences-in-birdson...
2•zeristor•39m ago•0 comments

Foundations of Metrology(1981) [pdf]

https://nvlpubs.nist.gov/nistpubs/jres/086/jresv86n3p281_A1b.pdf
1•pillars•46m ago•0 comments

Show HN: Self hosted video feed for children

https://github.com/vkolev/timmygram-server
1•vkolev•47m ago•0 comments

Open Source Does Not Imply Open Community

https://blog.feld.me/posts/2026/04/open-source-does-not-imply-open-community/
3•zdw•47m ago•1 comments

James Broadnax Executed After Being Sentenced to Death Based on Rap Lyrics

https://www.rollingstone.com/culture/culture-news/james-broadnax-executed-rap-lyrics-texas-123555...
3•latexr•48m ago•1 comments

Where would an offline fail-closed supervisor be useful?

https://madadh.systems
1•MADADAHSYSTEMS•53m ago•0 comments

CSS and vertical rhythm for text, images, and tables

https://vincent.bernat.ch/en/blog/2026-css-vertical-rhythm
1•vbernat•56m ago•0 comments

Sniffing EU Smart Meters with a Flipper Zero (WM-Bus / 868MHz)

https://github.com/i12bp8/wmbuster
1•i12bp8•1h ago•0 comments

GlowGoblin – a gift to mb pro users

https://github.com/jtc268/glowgoblin
1•husky8•1h ago•0 comments

Japan intervened in its Curreny price

https://www.fxstreet.com/news/usd-jpy-drops-over-2-as-intervention-warnings-lift-yen-after-move-a...
1•mark336•1h ago•1 comments

US telecom agency votes to expand tech crackdown on China

https://www.reuters.com/business/media-telecom/us-telecom-agency-votes-expand-tech-crackdown-chin...
5•l2dy•1h ago•0 comments

Anthropic Model inference runs fastest on AWS

https://twitter.com/theo/status/2050078772507124134
1•albert_e•1h ago•0 comments