frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Show HN: Stećak – a lightweight terminal inspired by Bosnian medieval tombstones

1•Ilikeruby•2m ago•0 comments

codyssey: turn every Claude Code session into a little adventure

https://github.com/delexw/codyssey
1•delexw•4m ago•0 comments

Show HN: SpeakUp – iOS app for feedback on your speaking (fillers, pauses, etc.)

https://apps.apple.com/gb/app/speak-up/id6760108342
1•__Srey__•4m ago•0 comments

Sift – An LLVM pass for speculative loop vectorization with E-graph SMT caching

https://github.com/sorenkhayes/sift
1•sorenkhayes•5m ago•0 comments

Making Sense of BigQuery Pricing Models

https://www.alvin.ai/blog/bigquery-pricing-models
1•Arimbr•5m ago•0 comments

Aleph Alpha and Mistral launches fuel Europe's sovereign AI push

https://www.renascence.io/news/96889/aleph-alpha-mistral-launches-fuel-europes-sovereign-ai-push
1•nonmaskable•7m ago•0 comments

[video] Pedagogy in the Times of AI

https://www.youtube.com/watch?v=N2a1J0UPeL4
1•newswasboring•8m ago•0 comments

Is This Machine Playing?

https://arxiv.org/abs/2610.07130
1•vinhnx•9m ago•0 comments

OpenClaw Foundation wins ICANN application for .claw top-level domain

https://twitter.com/steipete/status/2108374513931165759
4•soltanov•10m ago•0 comments

APX Forth: A Surprise

https://www.goto10retro.com/p/apx-forth-a-surprise
1•ibobev•16m ago•0 comments

Teen hike Claude Canada wilderness - emergency rescue

https://www.theguardian.com/world/2026/oct/08/teen-hike-claude-ai-directions-rescue-canada-mountain
1•mo7061•18m ago•0 comments

Sound and complete flow typing with unions, intersections and negations [pdf]

https://whileydave.com/publications/Pea13_VMCAI_preprint.pdf
1•fanf2•18m ago•0 comments

When No ID Means No Internet: Age Verification and Right to Access Information

https://www.eff.org/deeplinks/2026/10/when-no-id-means-no-internet-age-verification-and-right-acc...
1•mdp2021•20m ago•0 comments

Show HN: SpectroMood, speech emotion detection with a decision model

https://github.com/ketul93/spectromood
1•ketul_shah•20m ago•0 comments

RTSP to Virtual web cam in Rust

https://github.com/carl-eis/rtsp-rust-virtualcam
1•DistantCl3ric•21m ago•0 comments

EU faces gas supply shortage as winter looms

https://www.politico.eu/article/eu-faces-gas-supply-shortage-iran-war-winter-looms/
2•leonidasrup•23m ago•0 comments

Kubernetes for AI agents: when code is cheap, proof matters

https://kubedex.com/kubernetes-ai-agentic-development/
1•stevenacreman•26m ago•0 comments

Turn any app/website into an API

https://github.com/goodnight000/api-anything
1•goodnight000•28m ago•1 comments

AI has made it easier than ever to make apps nobody asked for

https://boakandbailey.com/2026/09/ai-has-made-it-easier-than-ever-to-make-apps-nobody-asked-for/
5•padraic7a•28m ago•2 comments

You are better than me

https://antejavor.github.io/blog/2026/you-are-better-then-me/
3•taubek•28m ago•0 comments

How to Automatically Redact Leaked API Keys and .env Files at the Edge

https://medium.com/@divinelab/how-to-automatically-redact-leaked-api-keys-and-env-files-at-the-ed...
1•divinelab•32m ago•0 comments

New AMOS PRO 3D Basic online

https://twitter.com/BlackCreepy_Cat/status/2108115762757984416
2•seyhajin•36m ago•0 comments

Welcome to Gemini at Work 2026: Introducing the Gemini Agent

https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026
2•oscarfr•38m ago•0 comments

The Two UX Gulfs: Evaluation and Execution – NN/G

https://www.nngroup.com/articles/two-ux-gulfs-evaluation-execution/
4•ankitg12•38m ago•1 comments

Prux is a minimal terminal coding agent

https://github.com/heng30/prux
1•heng30•39m ago•0 comments

Run Windows games (up to D3D9) in the browser

https://bottleship.pages.dev/
11•vasyop•39m ago•0 comments

Writing blog posts while walking the dog

https://jacobtomlinson.dev/posts/2026/writing-blog-posts-while-walking-the-dog/
2•tfader•40m ago•0 comments

What the interns have wrought, 2026 edition

https://blog.janestreet.com/wrought-2026/
2•s-zeng•40m ago•0 comments

Snyk is reporting false CVE

https://github.com/github/advisory-database/pull/10132
3•leyakak•44m ago•0 comments

Nuclear Weapon Storage Bunker

https://www.google.com/maps?q=Nuclear+weapon+storage+bunker,+kaliningrad&t=k
3•nomilk•45m ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.