frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Your Dog Might Be Eavesdropping on You

https://www.scientificamerican.com/article/some-dogs-learn-new-words-just-like-toddlers-do/
1•sohkamyung•3m ago•0 comments

Novel AI Method Sharpens 3D X-ray Vision

https://www.bnl.gov/newsroom/news.php?a=222627
1•cl3misch•5m ago•0 comments

Show HN: Where do my taxes go in Berlin? A personal receipt generator

https://berlin-bill.eamag.me
1•eamag•6m ago•0 comments

39C3 – Cracking Open What Makes Apple's Low-Latency WiFi So Fast [video]

https://media.ccc.de/v/39c3-cracking-open-what-makes-apple-s-low-latency-wifi-so-fast
1•amanverasia•7m ago•0 comments

Tik-Tok (Novel)

https://en.wikipedia.org/wiki/Tik-Tok_(novel)
1•firebaze•7m ago•0 comments

Pentagon is embracing Grok AI chatbot as it draws global outcry

https://apnews.com/article/artificial-intelligence-pentagon-hegseth-musk-7f99e5f32ec70d7e39cec92d...
1•geox•11m ago•1 comments

Show HN: Nametag – open-source personal relationships manager

https://nametag.one/
1•mattogodoy•12m ago•0 comments

European firms hit hiring brakes over AI and slowing growth

https://www.dw.com/en/european-eurozone-job-labor-market-unemployment-company-hiring-practice-cov...
1•smurda•13m ago•0 comments

Rewiring Mozilla: Doing for AI what we did for the web

https://blog.mozilla.org/en/mozilla/rewiring-mozilla-ai-and-web/
1•nalinidash•15m ago•0 comments

AI, AI Everywhere

1•okokwhatever•17m ago•0 comments

Physicians see 1 in 6 patients as 'difficult,' study finds

https://www.beckershospitalreview.com/patient-experience/physicians-see-1-in-6-patients-as-diffic...
1•Growtika•18m ago•1 comments

International central bankers stand in full solidarity with Powell

https://www.ecb.europa.eu/press/pr/date/2026/html/ecb.pr260113~ec4630b9fa.en.html
2•throw0101c•18m ago•2 comments

Boundary Enforcement in Code Review

1•mthssalome•21m ago•0 comments

Owners, not renters: Mozilla's open source AI strategy

https://blog.mozilla.org/en/mozilla/mozilla-open-source-ai-strategy/
1•nalinidash•22m ago•0 comments

Show HN: Janus – Anki flashcards from PDFs, videos and notes

https://janus.cards
1•A-F-V16•22m ago•1 comments

$999 RTX 5090 GPU scam claims 42 victims

https://www.tomshardware.com/pc-components/gpus/usd999-rtx-5090-gpu-scam-claims-42-victims-fanny-...
1•croes•22m ago•0 comments

People as Harmonic Oscillators

https://dogdogfish.com/blog/2026/01/13/people-as-oscillators/
2•matthewsharpe3•29m ago•1 comments

Hit squad recruiter for Sweden's Foxtrot criminal network arrested in Iraq

https://www.thenationalnews.com/news/mena/2026/01/13/hit-squad-recruiter-for-swedens-foxtrot-crim...
1•campuscodi•30m ago•0 comments

Show HN: MakersHub.dev – A community platform for people building with AI tools

https://makershub.dev/
1•adilmoujahid•30m ago•0 comments

Show HN: FreeMarker Support for Zed Editor

https://github.com/debba/zed-freemarker
1•debba•31m ago•0 comments

Ask HN: Quantum Computation, Computers and Programming

1•rramadass•34m ago•0 comments

Show HN: Policy-governed AI system for offline deployment in expertise deserts

https://github.com/thepoorsatitagain/Tutor-to-disaster-expert
1•thepoors•35m ago•0 comments

Podshop, the hedge fund game. As seen on Bloomberg's money stuff

https://www.podshop.io
1•WiseHare•35m ago•0 comments

Could Magic Mushrooms Have 'Woken Up' Our Ancestors?

https://thesporereport.com/?p=580
1•richrichardsson•36m ago•0 comments

WebUSB Unpinner: network analysis for the masses

https://reversing.works/posts/2025/12/webusb-unpinner-network-analysis-for-the-masses/
1•chobeat•37m ago•0 comments

Show HN: High-precision mouse polling rate tester

https://mousepollingratetest.com/
1•zylics•40m ago•1 comments

User authorization just got 10x harder

https://leaddev.com/event/user-authorization-just-got-10x-harder
2•mooreds•40m ago•0 comments

Ask HN: Infrastructure teams – what's your biggest compliance headache?

1•coppinfra•42m ago•0 comments

Iran official says 2k people have been killed in unrest

https://www.reuters.com/world/china/iranian-mp-warns-greater-unrest-urging-government-address-gri...
7•JumpCrisscross•43m ago•2 comments

Dullness and Disbelief: The 2026 AI Regression

https://vibesbench.substack.com/p/dullness-and-disbelief-the-2026-ai
2•firasd•43m ago•0 comments