frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Good Code, Wrong Feature: The Handoff Problem

https://productnow.ai/blogs/good-code-wrong-feature-the-handoff-problem
1•kadhirvelm•1m ago•1 comments

Deutsche Bahn blocks Linux users

https://www.heise.de/en/news/Deutsche-Bahn-No-information-under-Linux-11300847.html
1•cuechan•2m ago•0 comments

AI Makes Mistakes; Process Design Matters More

https://medium.com/@olowu.marydan/ai-makes-mistakes-that-means-process-design-matters-more-than-e...
1•centrali•3m ago•0 comments

Cities are investing tax dollars on trees. Here's why it works

https://www.marketplace.org/story/2026/05/19/why-cities-investing-in-trees-pays-off
1•mooreds•3m ago•0 comments

What's Next for Stephen Colbert After 'The Late Show'?

https://www.cnn.com/2026/05/20/media/what-is-stephen-colbert-doing-next-late-show-cbs
1•mooreds•3m ago•0 comments

The $100B Gen Alpha Economy [video]

https://www.youtube.com/watch?v=vCVGiB05MlA
1•mooreds•3m ago•0 comments

James Murdoch Buys Half of Vox Media

https://www.nytimes.com/2026/05/20/business/media/vox-media-james-murdoch-sale.html
1•littlexsparkee•5m ago•0 comments

Performative Blogging

https://joelchrono.xyz/blog/performative-blogging
1•speckx•6m ago•0 comments

560-610 minutes of exercise a week needed for substantial heart benefits

https://bmjgroup.com/560-610-minutes-of-exercise-a-week-needed-for-substantial-heart-benefits/
2•stevenwoo•6m ago•1 comments

Expedia Group to Acquire Cartrawler

https://www.rte.ie/news/business/2026/0520/1574346-cartrawler-agrees-deal-to-join-expedia-group/
1•thomasbolger•7m ago•0 comments

Aperion Shield: local guardrail that blocks destructive AI coding agent ops

https://github.com/AperionAI/shield
1•ScottAperion•9m ago•0 comments

What do the ropes at Shinto shrines mean? [video]

https://www.youtube.com/shorts/cwrlkaId_X0
1•keepamovin•9m ago•0 comments

Intuit Announces 17% Layoffs

https://old.reddit.com/r/cscareerquestions/comments/1tikket/intuit_announces_17_layoffs/
2•theanonymousone•9m ago•0 comments

Does Your Startup Need an AI Data Analyst?

https://www.hadijaveed.me/2026/05/18/byaan-agent-harness-for-data-queries/
1•hjaveed•10m ago•0 comments

Gemini 3.5 Flash: more expensive, but Google plan to use it for everything

https://simonwillison.net/2026/May/19/gemini-35-flash/
1•flyaway123•10m ago•0 comments

Show HN: Every Lego minifigure ranked, from over 1.3M user votes

https://brickelo.com
1•gpattle•10m ago•1 comments

Evidence-Graded Timelines

https://zeroagendanews.com/methodology/
1•factorialboy•11m ago•0 comments

Evolutionary Psychologist Gad Saad Explains the Woke Mind Virus (2024)

https://www.prageru.com/videos/evolutionary-psychologist-gad-saad-explains-the-woke-mind-virus-an...
1•neofrog•11m ago•0 comments

How Much of the Internet Is AI Slop?

https://www.statsignificant.com/p/how-much-of-the-internet-is-ai-slop
2•prismatic•12m ago•0 comments

Toast gets a website redesign to celebrate its system theme

https://paradise-runner.github.io/toast/
1•dividedcomet•14m ago•1 comments

We've entered a golden age of idea thieves and liars

https://www.machinesociety.ai/p/weve-entered-a-golden-age-of-idea
2•mikelgan•15m ago•1 comments

Execs admit AI makes them value human workers less

https://www.theregister.com/ai-ml/2026/05/13/execs-admit-ai-makes-them-value-human-workers-less/5...
1•samtrack2019•16m ago•0 comments

Mast Climber

https://nabkmastclimber.com
1•youssefmaia•16m ago•1 comments

Mass surveillance of foreigners in China revealed by abandoned demo dashboard

https://netaskari.substack.com/p/sharp-eyes-how-to-track-a-foreigner
3•ilamont•17m ago•0 comments

LLM INQUISITOR: Evaluating how AI models handle long, realistic tasks

https://github.com/AssimilatedHuman/LLM-Inquisitor
1•ballista2026•17m ago•0 comments

A self-hosted, unified webmail client

https://github.com/maathimself/mailflow
1•goldfish8543•17m ago•0 comments

Scheduled GitHub Actions are now useless

https://www.viblo.se/posts/scheduled-gh-actions/
2•viblo•19m ago•0 comments

Map of music

https://toposonico.com/#lon=10.0593&lat=-4.5548&z=6.56&entity=track&rowid=8714
2•deppep•20m ago•0 comments

America's Greatest Strategic Blunder: The Imprisonment of Qian Xuesen

https://danieltan.weblog.lol/2026/05/americas-greatest-strategic-blunder-the-imprisonment-of-qian...
21•danieltanfh95•22m ago•2 comments

Show HN: One dev environment for humans, CI, and AI agents

https://ralch.com/blog/one-dev-environment-for-humans-ci-and-agents/
1•svett•22m ago•0 comments