frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

I Taught an AI to Be Our On-Call Engineer

https://medium.com/pipedrive-engineering/scooby-how-i-taught-an-ai-to-be-our-on-call-engineer-163...
1•devuo•1m ago•0 comments

VCs invested $300B in agentic infrastructure in Q1 2026

https://www.hitechies.com/venture-capital-q1-2026-300-billion-agentic-infrastructure-founders/
1•dhakalster•2m ago•0 comments

Value creation, bullshit jobs and the future of work

https://seths.blog/2026/05/value-creation-bullshit-jobs-and-the-future-of-work/
1•swolpers•3m ago•0 comments

The Cache Aware Scheduling Looks Like It Will Land for Linux 7.2

https://www.phoronix.com/news/Linux-7.2-Likely-CAS
1•rbanffy•5m ago•1 comments

Show HN: Visual timezone converter for remote teams

https://fluttertime.com/
1•dbecks•6m ago•0 comments

Mummy Brown

https://en.wikipedia.org/wiki/Mummy_brown
1•thunderbong•6m ago•0 comments

No Slop Grenade

https://noslopgrenade.com/
1•napolux•8m ago•0 comments

Show HN: I am making a cat-based gamified productivity app

https://store.steampowered.com/app/4704810/Junebug/
1•egretfx•10m ago•0 comments

X-Plane 12 Citation-X Checklist

https://www.wedesoft.de/simulation/2026/05/10/x-plane-citation-x-checklist/
1•wedesoft•10m ago•1 comments

The Beatles – On Their Old Sound

https://medium.com/the-hitmagist/the-beatles-on-their-old-sound-af380e576227
1•bryanrasmussen•11m ago•0 comments

Engineering Manager Interview Preparation

https://yusufaytas.com/engineering-manager-interview-preparation
7•hunter_coder•12m ago•0 comments

Gauss List Sieve for Lattices

https://leetarxiv.substack.com/p/gauss-lll-sieve
2•theanonymousone•13m ago•1 comments

AI token streaming isn't about SSE vs. WebSockets

https://zknill.io/posts/ai-token-streaming-isnt-about-sse-vs-websockets/
1•zknill•15m ago•0 comments

The Largest Sewer-Heat Recovery System in North America

https://nationalwesterncenter.com/about/what-is-the-nwc/sustainability-regen/energy/
1•geox•15m ago•0 comments

Nvidia raises video encoder limit to 12 on consumer GPUs

https://developer.nvidia.com/video-encode-decode-support-matrix
2•andrewstuart•18m ago•0 comments

Show HN: Rmux – A programmable terminal multiplexer with a Playwright-style SDK

https://github.com/helvesec/rmux
5•shideneyu•18m ago•0 comments

Hardware LLM Taalas Reaches >14,000 TPS on Llama 3.1 8B

https://taalas.com/products/
1•nullbio•19m ago•1 comments

Mind Citadel: Quiz RPG. New trivia game with RPG taste

https://play.google.com/store/apps/details?id=com.sektor.mindcitadel&hl=en_US
1•xSeKToRx•19m ago•1 comments

NASA's Psyche spacecraft returns unfamiliar views of a familiar world

https://arstechnica.com/space/2026/05/nasas-psyche-spacecraft-returns-unfamiliar-views-of-a-famil...
1•rbanffy•19m ago•0 comments

Gembokwarkop: Base64-Vigenere vs. AIs

https://github.com/altilunium/gembokwarkop
1•altilunium•19m ago•0 comments

Managers Have Been Vibe Coding All Along

https://yusufaytas.com/managers-have-been-vibe-coding-all-along
7•wyajmd•20m ago•0 comments

Anthropic on track for first profitable quarter

https://www.ft.com/content/a67248e7-f819-4dba-b0f7-3847df0a75f3
2•throwaway2037•23m ago•0 comments

Show HN: Real-time virtual try-on using hand gestures and live video diffusion

https://github.com/manas15/try-on
9•manas95•24m ago•1 comments

Large-Scale High-Quality 3D Gaussian Head Reconstruction from Multiview Captures

https://apple.github.io/ml-headsup/
2•epaga•24m ago•0 comments

AI Engineering from Scratch

https://aiengineeringfromscratch.com
2•rippeltippel•25m ago•0 comments

The US space enterprise is desperately waiting for Starship–will it deliver?

https://arstechnica.com/space/2026/05/the-us-space-enterprise-is-desperately-waiting-for-starship...
1•rbanffy•26m ago•0 comments

Anthropic is paying SpaceX $1.25B/month and other things hidden in the S-1

https://italianelite.eu/articles/spacex-s1-deep-dive.html
2•johntiror•26m ago•0 comments

I built a tool that critiques SaaS landing pages

https://pagegains.com
1•solopreneur_dad•27m ago•0 comments

Earth's supervolcanoes are waking up. Here's what that means for the planet

https://www.sciencefocus.com/planet-earth/earths-supervolcanoes-are-waking-up-heres-what-that-mea...
2•bryanrasmussen•27m ago•0 comments

Fuck YAML

https://github.com/IronScheme/IronScheme/commit/2f847793946935bd9143cdfb064f9006f763df68
1•theanonymousone•31m ago•0 comments