frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

You're Right

https://youre-absolutely-right-one.vercel.app/
1•senko•34s ago•0 comments

Antares Achieves Criticality of Mark-0 Reactor

https://antaresindustries.com/updates/antares-achieves-criticality
1•clarionbell•1m ago•0 comments

The Shape of the Whole

https://shapeofthesystem.com/the-shape-of-the-whole
1•charlieirish•8m ago•0 comments

RPC Endpoints

https://rpc.uquad.org/
1•uquad•8m ago•0 comments

After 12 years of being a customer, Uber is dumping PagerDuty

https://twitter.com/GergelyOrosz/status/2071709320199164184
1•tosh•9m ago•0 comments

The Invisible Architecture of Lock-In

https://blog.documentfoundation.org/blog/2026/06/30/the-invisible-architecture-of-lock-in/
2•ilreb•15m ago•0 comments

Show HN: Rheo 0.4.0

https://github.com/freecomputinglab/rheo
1•breezykermo•15m ago•0 comments

Database Traffic Control

https://planetscale.com/blog/introducing-database-traffic-control
1•religio•17m ago•0 comments

Paris deputy mayor blames the US's carbon emissions for deadly heat wave

https://www.foxnews.com/media/paris-deputy-mayor-blames-united-states-carbon-emissions-deadly-hea...
1•TMWNN•18m ago•0 comments

Show HN: Crosswalk mapping AI-agent design controls to NIST, ISO 42001, OWASP

https://www.agent-kits.com/agentaz-crosswalk
1•stoicstoic•18m ago•0 comments

Gojek founder Nadiem Makarin sentenced to jail in Indonesia corruption case

https://www.bbc.com/news/articles/c79yvw23yr9o
1•doppp•20m ago•0 comments

FitAge – functional age from 8 physical tests (open source)

https://fitage.thehumanruntime.com/
1•filipacsr•21m ago•1 comments

Show HN: Availability Tracker – A Simple Way to Track Items

https://availabilitytracker.app/
1•jkferland•23m ago•0 comments

History of T

https://paulgraham.com/thist.html
2•tosh•25m ago•0 comments

Show HN: Window Switcher – Better same-app window switching for macOS

https://github.com/hanguokai/window-switcher
1•hanguokai•26m ago•0 comments

Oura Ring 5 Review

https://www.theguardian.com/technology/2026/jun/30/oura-ring-5-review-smart-ring-health-tracking
2•tosh•26m ago•0 comments

Show HN: Escalate – human as a service for your agent

https://escalateto.me/landing
1•oleh_vell•26m ago•0 comments

Webhookvault

https://webhookvault.onrender.com/login
1•hydra2297•27m ago•0 comments

Belgian politicians would rather risk treason charges than trust engineers

https://mikhailian.mova.org/posts/325-belgian-politicians-would-rather-risk-treason-charges-than-...
1•sam_lowry_•27m ago•0 comments

Stop the Tester's Inferiority Complex: QA and Dev Are Equals

https://medium.com/@vincent.ferreira/stop-the-testers-inferiority-complex-qa-and-dev-are-equals-9...
1•vincenfer•28m ago•0 comments

The Scanline Sweeper: A Glyph Rendering Algorithm [video]

https://www.youtube.com/watch?v=B9bztU1sTFA
1•alan665•28m ago•0 comments

Vantor's Open Satellite Feed

https://tech.marksblogg.com/vantor-satellite-imagery.html
1•marklit•29m ago•0 comments

Apple acquires Play, award-winning SwiftUI prototyping tool

https://www.cultofmac.com/news/apple-acquires-play-swiftui-app
1•terelueli•33m ago•0 comments

Show HN: WtfisMyRepo – Use Claude to understand most complex codebases in mins

https://github.com/nandnijaiswal/wtfismyrepo
2•udit_50•33m ago•1 comments

Beyond Denial How Oil Execs Shaped a Landmark Climate Study

https://www.propublica.org/article/wedges-climate-research-bp-fossil-fuel-princeton
1•_____k•34m ago•0 comments

Porting half life 2 to the browser

https://www.slqnt.dev/blog/hl2-in-web
1•QuantumNomad_•35m ago•0 comments

Show HN: Classic Minesweeper

https://guokai.dev/minesweeper/
1•hanguokai•36m ago•0 comments

China's Geely to Ship First Lotus EVs to Canada

https://www.reuters.com/world/asia-pacific/chinas-geely-ship-first-lotus-evs-canada-july-under-ca...
1•Alien1Being•42m ago•0 comments

Show HN: Mocca – A Mac email client powered by local AI

https://mocca.run/
1•brighbun•42m ago•0 comments

A Framework for Representing Knowledge – Marvin Minsky (1975) [pdf]

https://courses.media.mit.edu/2004spring/mas966/Minsky%201974%20Framework%20for%20knowledge.pdf
1•the-mitr•43m ago•0 comments