frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•10mo ago

Comments

kemotep•10mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Weave – A language aware merge algorithm based on entities

https://github.com/Ataraxy-Labs/weave
1•rs545837•3m ago•0 comments

Defense contractors removing Anthropic's AI after Trump ban

https://www.reuters.com/sustainability/society-equity/defense-contractors-like-lockheed-seen-remo...
1•alephnerd•8m ago•0 comments

Fubar Daily – Dystopian news for a jaded generation

https://www.fubardaily.com
1•anonnona8878•8m ago•1 comments

Intel Nova Lake-Ax for Local LLMs – Rumored AMD Strix Halo Competitor (2025)

https://www.hardware-corner.net/intel-nova-lake-ax-local-llms/
1•walterbell•10m ago•0 comments

A rabbi is overseeing Pornhub. That's not so weird – The Forward

https://forward.com/culture/654804/pornhub-rabbi-solomon-friedman-jewish/
1•vinnyglennon•11m ago•1 comments

Show HN: Ukcalculator.com – Free UK tax, salary and mortgage calculators

https://ukcalculator.com/
1•mystart•11m ago•0 comments

Show HN: AgentBus – Centralized AI Agent-to-Agent Messaging via REST API

https://agentbus.org/
2•notepstein•13m ago•0 comments

QuarterBit – Train 70B LLMs on a single GPU

https://quarterbit.dev
2•quarterbit•15m ago•2 comments

Show HN: AI agent that trades Polymarket by hiring inference via Lightning

https://trader.lpxpoly.com
2•LightProx•17m ago•0 comments

Show HN: I built a S3 proxy that combines storage from S3/clouds into one target

https://github.com/afreidah/s3-orchestrator
2•munch-o-man•19m ago•0 comments

Iranian Number Station

https://www.iz0kba.it/en/iranian-number-station/
3•pabs3•20m ago•0 comments

OB-1

https://www.openblocklabs.com/
3•handfuloflight•20m ago•0 comments

Free software needs free tools

https://lwn.net/SubscriberLink/1060649/f0e94c3b1b4fe3bc/
4•pabs3•21m ago•0 comments

Cybersecurity and Ethical Hacking Cheatsheets

https://github.com/Ilias1988/Hacking-Cheatsheets
4•Ilias1988•21m ago•1 comments

Accenture down to buy Downdetector as part of $1.2B deal

https://www.theregister.com/2026/03/03/accenture_buys_ookla_downdetector_ziff_davis/
3•cebert•24m ago•0 comments

Tectonic good project plan: Please read

2•fourwindsoh•24m ago•1 comments

TikTok won't protect DMs with E2EE, saying it would put users at risk

https://www.bbc.com/news/articles/cly2m5e5ke4o
2•1659447091•24m ago•0 comments

2,218 Gary Marcus AI claims scored against evidence (dataset)

https://github.com/davegoldblatt/marcus-claims-dataset
43•davegoldblatt•25m ago•16 comments

The largest acidic geyser has been putting on quite a show

https://www.usgs.gov/observatories/yvo/news/echinus-geyser-back-action-now
2•1659447091•28m ago•0 comments

The Xkcd thing, now interactive, as jenga blocks

https://jenga.symploke.dev/
2•thomasfromcdnjs•31m ago•0 comments

Help us test WEBCAT alpha

https://securedrop.org/news/webcat-alpha/
2•ahlCVA•32m ago•0 comments

Bankster: Money as Data

https://github.com/randomseed-io/bankster
2•PaulHoule•33m ago•0 comments

Show HN: Augur – A text RPG boss fight where the boss learns across encounters

https://www.theaugur.ai/
3•thutch76•36m ago•1 comments

AgentMail Now Supports X402

https://twitter.com/agentmail/status/2028893166506787270
2•obulbo•36m ago•1 comments

Progressive Disclosure CLI for OpenAPI

https://github.com/OpenScribbler/phyllotaxis
2•mlhpdx•39m ago•0 comments

Show HN: A leadership 360 survey for startup founders: feedback please

https://org360.app/surveys/startup-founder-360
2•ddesposito•43m ago•1 comments

Python Package Uses a PRNG-Like Algorithm to Create Tokenized Infinite Data

https://github.com/stateshaper/stateshaper/tree/old_main
2•jaygeorgedunn•44m ago•0 comments

The 'Anything-but-Solar' Trade Is the Future of Solar

https://www.bloomberg.com/opinion/articles/2026-03-03/the-anything-but-solar-trade-is-the-future-...
2•petethomas•46m ago•0 comments

Show HN: OpenClawHub – A Lib for AI agent workflows so you don't have to

https://openclawhub.uk/
2•951560368•46m ago•0 comments

Critical Authentication Bypass in Pac4j-JWT – Using Only a Public Key

https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key
3•Brajeshwar•51m ago•0 comments