frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Bond: A new AI social network that turns memories into discoveries

https://www.bond.now/
1•johndavisonr•49s ago•0 comments

Nothing ever dies. It merely becomes embarrassing

https://www.experimental-history.com/p/nothing-ever-dies-it-merely-becomes
1•paulpauper•1m ago•0 comments

The New Age of Performance Anxiety

https://www.theatlantic.com/culture/2026/04/screen-people-stage-fright-performance-anxiety/686803/
1•paulpauper•2m ago•0 comments

What It's Like to Live with an Experimental Brain Implant

https://spectrum.ieee.org/bci-user-experience
1•digital55•2m ago•0 comments

Wearable health tech might be Tim Cook's greatest legacy

https://www.theverge.com/tech/915976/tim-cook-john-ternus-apple-watch-health-tech-wearables
1•paulpauper•2m ago•0 comments

The Fossils 1969

https://www.youtube.com/watch?v=bn1uhSS1cDo
1•indigodaddy•2m ago•0 comments

Amtrak's "1MB" National Route Map PDF Is a 574MB File

https://www.amtrak.com/train-routes
1•tech234a•3m ago•0 comments

Iconiq, Go-To Wealth Adviser for Tech's Elite, Is Putting Billions into AI

https://www.bloomberg.com/news/articles/2026-04-17/iconiq-advisor-to-tech-billionaires-emerges-as...
1•petethomas•3m ago•0 comments

The power keeping wages low

https://text.npr.org/g-s1-118071
1•mooreds•3m ago•0 comments

InvenTree: Open-source inventory management system with OpenAPI

https://github.com/inventree/InvenTree
1•matmair•5m ago•1 comments

Brex founder open sourced his stack for running the company through OpenClaw

https://github.com/brexhq/CrabTrap
1•ofabioroma•5m ago•1 comments

Cube Sandbox: Instant, Concurrent, Secure and Lightweight Sandbox for AI Agents

https://docs.cubesandbox.ai/
1•bpierre•6m ago•0 comments

Plastic film covered in tiny pillars can tear apart viruses on contact

https://theconversation.com/new-plastic-film-covered-in-thousands-of-tiny-pillars-can-tear-apart-...
2•geox•6m ago•0 comments

Privacy raised during teen social media ban tech trial were ignored

https://www.themandarin.com.au/311397-privacy-raised-during-teen-social-media-ban-tech-trial-were...
1•cdrnsf•7m ago•0 comments

OpenAI Shuts Down Sora AI? But Why?

https://www.bbc.com/news/articles/c3w3e467ewqo
2•shockedstorys•12m ago•0 comments

Show HN: FMQL – graph query and bulk-edit CLI for Markdown and YAML frontmatter

https://github.com/buyuk-dev/fmql
1•buyukdev•12m ago•1 comments

Retro Rewind – Video Store Simulator

https://store.steampowered.com/app/3552140/Retro_Rewind__Video_Store_Simulator/
1•doener•13m ago•0 comments

Can you spend $600K on B300 GPU Server? Which LLM will you run on this?

https://www.dihuni.com/
1•tech_curator•14m ago•0 comments

The Deskilling Paradox

https://signalintent.net/2026/04/21/the-deskilling-paradox/
1•tokonomy_dev•16m ago•0 comments

Lotus Wiper: a new threat targeting the energy and utilities sector

https://securelist.com/tr/lotus-wiper/119472/
1•campuscodi•16m ago•0 comments

Perry, a TypeScript compiler written in Rust that targets nine platforms

https://www.perryts.com/
1•bpierre•16m ago•0 comments

What Drives AI Crawler Traffic?

https://www.searchenginejournal.com/68-million-ai-crawler-visits-show-what-drives-ai-search-visib...
1•restlessforge•16m ago•1 comments

NSA loads Anthropic Mythos cyberattack while Pentagon says it cannot

https://aitwerp.com/signals/nsa-cyberattack-consent-bypassed/
1•Inziu•18m ago•0 comments

Delegation as an OS Primitive

https://mz.attahri.com/posts/delegation-as-os-primitive/
1•mohamedattahri•20m ago•0 comments

Stop Paying the JSON Tax

https://columnar.tech/blog/stop-paying-the-json-tax//
1•ianmcook•21m ago•0 comments

Moving On

https://marcg.net/moving-on/
1•speckx•22m ago•1 comments

Google taps Sergey Brin to lead a specialized AI strike team to take on Claude

https://www.msn.com/en-in/money/news/google-taps-sergey-brin-to-lead-a-specialized-ai-strike-team...
1•rantingdemon•23m ago•0 comments

Mhdybnb

https://blog.cloudflare.com/post-quantum-warp/
1•mhdybnb•24m ago•0 comments

One unusual thing in SV is the topics of billboard ads

https://101ads.org/
3•mihaichiorean•24m ago•1 comments

U.S. Attorney's Office Filed 143 Border-Related Cases This Week

https://www.justice.gov/usao-sdca/pr/us-attorneys-office-filed-143-border-related-cases-week
1•737min•27m ago•1 comments