frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Verification-Driven Development (VDD) via Iterative Adversarial Refinement

https://gist.github.com/dollspace-gay/45c95ebfb5a3a3bae84d8bebd662cc25
1•sebg•1m ago•0 comments

Shared State Context for AI Agents [Ask/Show][Looking for Beta]

1•aperi•2m ago•0 comments

The Zcash core dev team has resigned

https://twitter.com/tedpillows/status/2009206637962383809
1•simonebrunozzi•4m ago•0 comments

Testmon – Speed up your test suite in CI

https://testmon.net
1•drcongo•5m ago•0 comments

Execline: A Small Scripting Language

http://skarnet.org/software/execline/
1•fanf2•8m ago•0 comments

I Drilled Holes in My $200 Waterproof Panniers

https://cycletouring.substack.com/p/i-drilled-holes-in-my-200-waterproof
1•djrivard•8m ago•0 comments

Wigner Cat Phases: Transition to Quantum Chaos

https://arxiv.org/abs/2512.22169
1•northlondoner•9m ago•1 comments

Show HN: Analytics for SaaS Founders Connecting Stripe, Google Analytics and GSC

https://busel.ai/
1•stasman•9m ago•0 comments

Is Claude Ret***ed? Website where you vote on Claude's daily stupidity

https://www.isclauderetarded.today/
1•skrabe•10m ago•1 comments

Why Deepfake Technology Forces Courts to Rethink the Reliability of Evidence

https://www.technologylaw.ai/p/deepfake-technology-evidentiary-reliability-courts
1•pcaharrier•10m ago•0 comments

Beyond Training: Enabling Self-Evolution of Agents with Mobimem

https://arxiv.org/abs/2512.15784
1•PaulHoule•14m ago•0 comments

Trend Hacking 2025: The Niche Protocol for Founders

https://blog.vect.pro/trend-hacking-guide
1•WoWSaaS•15m ago•1 comments

One Regulation E, Two Different Regimes

https://www.bitsaboutmoney.com/archive/regulation-e/
1•gmcharlt•15m ago•0 comments

The revolution will be televised with QR codes

https://twitter.com/omid9/status/2009049147786104841
1•tim333•15m ago•0 comments

Dutch Fintech Bunq Reapplies to Become a Bank in the US

https://www.bloomberg.com/news/articles/2026-01-07/dutch-fintech-bunq-reapplies-to-become-a-bank-...
1•teekert•16m ago•1 comments

PCSX2 2.6.0

https://pcsx2.net/blog/2025/pcsx2-2.6/
1•wubin•19m ago•0 comments

Hypocritespy(HTTPS://github.com/Ronny12345-art/Hypocritespy)

1•Ronny12345-art•20m ago•0 comments

Correlation Between the Use of Swearwords and Code Quality in Open Source Code [pdf]

https://cme.h-its.org/exelixis/pubs/JanThesis.pdf
1•pantalaimon•21m ago•0 comments

The sub-zero lair of the most powerful computer

https://www.bbc.co.uk/news/articles/c62r6dvpl5ro
1•Isofarro•24m ago•0 comments

GhostShield – A Python-Based DNS Sinkhole for Raspberry Pi Zero

https://github.com/Reazonay/GhostShield
2•Reazonay•28m ago•1 comments

What's the difference between NYC and Caracas?

https://zoneofsulphur.substack.com/p/whats-the-difference-between-nyc
2•Zone_of_Sulphur•28m ago•0 comments

When Aging Becomes a Felony

https://zoneofsulphur.substack.com/p/when-aging-becomes-a-felony
2•Zone_of_Sulphur•29m ago•1 comments

AI and the Next Economy

https://www.oreilly.com/radar/ai-and-the-next-economy/
1•mindcrime•30m ago•0 comments

Pentagon Pizza Theory

https://en.wikipedia.org/wiki/Pentagon_pizza_theory
1•thunderbong•30m ago•0 comments

A Letter Won't Always Be Postmarked the Same Day You Drop It in the Mail

https://www.wsj.com/politics/policy/a-letter-wont-always-be-postmarked-the-same-day-you-drop-it-i...
2•bookofjoe•35m ago•1 comments

OpenAI has launched ChatGPT Health. Should we trust it?

https://restofworld.org/2026/openai-has-launched-chatgpt-health-should-we-trust-it/
1•donohoe•38m ago•1 comments

FFmpeg Thanks to TencentGlobal

https://twitter.com/i/status/2008537909008515541
2•engcountio•40m ago•1 comments

How Bright Headlights Escaped Regulation – and Blinded Us All

https://www.autoblog.com/news/how-bright-headlights-escaped-regulation-and-blinded-us-all
6•pseudolus•40m ago•0 comments

Show HN: I built a multi-agent "Boardroom" to roast my startup ideas

https://www.roundtablelabs.ai/
2•maxkuan•41m ago•0 comments

Nw_wrld: Event-driven sequencer for triggering visuals

https://github.com/aagentah/nw_wrld
1•amar-laksh•42m ago•0 comments