frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•7mo ago

Comments

kemotep•7mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

"Why would anybody start a website?"

https://daverupert.com/2025/09/why-would-anybody-start-a-website/
1•cdrnsf•3m ago•0 comments

I wrote JustHTML using coding agents

https://friendlybit.com/python/writing-justhtml-with-coding-agents/
1•alsetmusic•5m ago•1 comments

SPhotonix – 360TB into 5-inch glass disc with femtosecond laser

https://www.tomshardware.com/pc-components/storage/sphotonix-pushes-5d-glass-storage-toward-data-...
1•peter_d_sherman•5m ago•0 comments

Anesthesia Experiments Are Reviving Quantum Consciousness Theories

https://www.popularmechanics.com/technology/a69632925/quantum-consciousness-anesthesia-experiments/
1•bookofjoe•6m ago•1 comments

How the US freight rail industry got dirtier than coal power plants

https://www.reuters.com/sustainability/climate-energy/how-us-freight-rail-industry-got-dirtier-th...
1•geox•8m ago•0 comments

CapROS: The Capability-Based Reliable Operating System

https://www.capros.org/
1•gjvc•11m ago•0 comments

Layer Normalization as Fast as Possible

https://fleetwood.dev/posts/layernorm-as-fast-as-possible
1•montyanderson•13m ago•0 comments

Robot Vacuum Roomba Maker Files for Bankruptcy After 35 Years

https://news.bloomberglaw.com/bankruptcy-law/robot-vacuum-roomba-maker-files-for-bankruptcy-after...
5•nreece•14m ago•1 comments

Skövde, the tiny town powering up Sweden's video game boom

https://www.theguardian.com/games/2025/dec/12/skovde-sweden-video-games-goat-simulator-valheim-v-...
1•1659447091•15m ago•0 comments

Microsoft Copilot AI Comes to LG TVs, and Can't Be Deleted

https://www.techpowerup.com/344075/microsoft-copilot-ai-comes-to-lg-tvs-and-cant-be-deleted
2•akyuu•15m ago•0 comments

TV in America, Pt. 1 – Foundations

https://drmanhattan16.substack.com/p/the-history-of-tv-in-america-pt-1
1•paulpauper•16m ago•0 comments

Oliver Sacks fabricated key details in his books

https://boingboing.net/2025/12/12/oliver-sacks-fabricated-key-details-in-his-books.html
3•paulpauper•19m ago•1 comments

Frances Elizabeth Allen: The Woman Who Made Code Run Fast – and Was Forgotten

https://voxmeditantis.com/2025/12/13/frances-elizabeth-allen-the-woman-who-made-code-run-fast-and...
3•colinprince•20m ago•1 comments

Being There: On Working in Person

https://medium.com/@maspinwall22/being-there-5c167dd8b163
1•govmaspy•21m ago•1 comments

Ask HN: Best back end to run models on Google TPU?

2•vood•26m ago•0 comments

Grok is spreading misinformation about the Bondi Beach shooting

https://www.theverge.com/news/844443/grok-misinformation-bondi-beach-shooting
3•alsetmusic•28m ago•1 comments

Ravaan.art

https://ravaan.art/?seed=71dafa3svng
2•nateb2022•29m ago•0 comments

Sam Altman's Sprint to Correct OpenAI's Direction and Fend Off Google

https://www.wsj.com/tech/ai/openai-sam-altman-google-code-red-c3a312ad
1•babelfish•29m ago•1 comments

Larry Wall, the Guru of Perl (1999)

https://www.linuxjournal.com/article/3394
2•susam•30m ago•0 comments

If AI replaces workers, should it also pay taxes?

https://english.elpais.com/technology/2025-11-30/if-ai-replaces-workers-should-it-also-pay-taxes....
5•PaulHoule•34m ago•0 comments

UK Treasury drawing up new rules to police cryptocurrency markets

https://www.theguardian.com/technology/2025/dec/15/uk-treasury-drawing-up-new-rules-to-police-cry...
3•chrisjj•35m ago•0 comments

L5: A Processing Library in Lua for Interactive Artwork

https://l5lua.org/
2•azhenley•36m ago•0 comments

A Year of Not Really Blogging

https://duggan.ie/posts/a-year-of-not-really-blogging
1•duggan•37m ago•0 comments

Adding Bits Beats AI Slop

https://gwern.net/blog/2025/good-ai-samples
2•networked•37m ago•0 comments

JSDoc types are not TypeScript types

https://jcbhmr.com/2024/12/24/jsdoc-is-not-ts/
3•jcbhmr•37m ago•0 comments

Whisper-Turbo – Cross-Platform, GPU Accelerated Whisper

https://github.com/FL33TW00D/whisper-turbo
1•montyanderson•38m ago•0 comments

Scripting on the Lido Deck (2000)

https://web.archive.org/web/20160307004219/http://www.wired.com/2000/10/cruise/
1•susam•40m ago•0 comments

Marc Andreessen and Charlie Songhurst on the past, present, and future [video]

https://www.youtube.com/watch?v=E_1cTlLpNMg
1•montyanderson•42m ago•0 comments

If you hate networking, you're probably bad at it

https://adelwu.substack.com/p/if-you-hate-networking-youre-probably
2•swyx•43m ago•0 comments

The World Is Not a Desktop (1994)

https://dl.acm.org/doi/pdf/10.1145/174800.174801
3•todsacerdoti•47m ago•0 comments