frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Containers are great. Kubernetes is great. But [DBA crying]

https://www.reddit.com/r/PostgreSQL/s/ZgXjnVg4T4
1•vitabaks•27s ago•1 comments

pyqwest

https://pyqwest.dev/
1•tosh•1m ago•0 comments

CVEs in UniFi Security Advisory Bulletin 067

https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96d...
1•doublepg23•3m ago•0 comments

Cherish your physical books and media

https://www.dedoimedo.com/life/books-dvds.html
1•speckx•3m ago•0 comments

Compiling Agent Experience into Persistent Knowledge for Skill Evolution

https://arxiv.org/abs/2608.27454
1•tcp_handshaker•3m ago•0 comments

Proxy Web GUI inspector coming to rama CLI in 0.5

https://plabayo.tech/blog/rama-cli-0-5-proxy-inspector
1•gdcbe•4m ago•1 comments

LLMs Can Design Near-Optimal OR Algorithms

https://arxiv.org/abs/2608.27296
1•tcp_handshaker•6m ago•0 comments

Your MCP Client Trusts Too Much: What a Capability Layer Stops

https://naftiko.io/blog/your-mcp-client-trusts-too-much/
1•jlouvel•10m ago•0 comments

What Remains of the SPR Is Probably Less Useful Than You Think

https://oureconomydoesntwork.substack.com/p/what-remains-of-the-spr-is-probably
1•oureconomydoesn•12m ago•0 comments

Show HN: I read 648 banks' exchange boards daily to show what they charge

https://myratefx.com/
1•pedroalbaladejo•12m ago•0 comments

OpenOffice does not print on Tuesdays (2009)

https://beza1e1.tuxen.de/lore/print_on_tuesday.html
1•birdculture•12m ago•0 comments

Show HN: Free lifetime pro access to a crunchbase alternative

https://startupwiki.tech/giveaway
1•skiski•14m ago•0 comments

BioNTech halts mRNA colorectal cancer vaccine trial after review

https://www.reuters.com/business/healthcare-pharmaceuticals/biontech-terminate-mid-stage-trial-mr...
4•cwwc•15m ago•0 comments

Let's fix indecipherable public data with Al

https://www.digitaldigging.org/p/lets-fix-chaotic-public-data-with
2•techtracer•15m ago•0 comments

Mobile Games Designed to Be Addictive Get More Kid-Friendly

https://www.bloomberg.com/graphics/2026-kid-friendly-mobile-games-addiction/
4•BloodOrb2•17m ago•0 comments

Japan's 3D Modeling Philosophy [video]

https://www.youtube.com/watch?v=p-i9o-sHV7k
2•Ariarule•17m ago•0 comments

Birding Like It's 1899: Inside a Blockbuster American West Video Game (2019)

https://www.audubon.org/magazine/birding-its-1899-inside-blockbuster-american-west-video-game
2•Tomte•20m ago•0 comments

AI GPUs probably live longer than three years

https://www.seangoedecke.com/ai-gpus-live-longer-than-three-years/
3•fagnerbrack•21m ago•0 comments

Just the rumour of a bug is enough to find an exploit these days

https://anil.recoil.org/notes/rumour-is-the-exploit
11•avsm•23m ago•2 comments

Blue-Collar Jobs Are the New Flashpoint in Data-Center Fight

https://www.wsj.com/economy/jobs/blue-collar-jobs-are-the-new-flashpoint-in-data-center-fight-aac...
5•JumpCrisscross•24m ago•0 comments

Nvidia Insists It Can Keep Printing Money to Fund the AI Boom

https://www.wsj.com/tech/ai/nvidia-insists-it-can-keep-printing-money-to-fund-the-ai-boom-195e7d5e
10•root-parent•24m ago•7 comments

Investigation of agents' behavior in the OpenAI/HuggingFace hacking incident

https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
5•thunderbong•26m ago•0 comments

Agent ROI, Sales Overriding Roadmap, Forcing Your Disruption

https://age-of-product.com/food-agile-thought-559-agent-roi/
3•swolpers•27m ago•0 comments

OpenAI Flailed Through a Maze

https://ninjasandrobots.com/maze
4•nate•28m ago•1 comments

Telnyx Email API is now generally available

https://telnyx.com/release-notes/email-api-now-generally-available
3•telnyxnews•31m ago•1 comments

Trump's Working to Give Part of Yosemite to a Private Developer

https://www.notus.org/agencies/trump-administration-yosemite-private-developer-deal
7•divbzero•32m ago•2 comments

Proof that your data is worth more than charging for any product

https://timemachiner.io/2026/08/27/proof-that-your-data-is-worth-more-than-charging-for-any-product/
3•speckx•32m ago•0 comments

OpenAI gates cyber defense in 44 ChatGPT markets with a 1996 US export list

https://lubaretsi.com/en/writing/openai-tac-country-gate/
2•glub•32m ago•0 comments

I Signed Up for Claude Pro, Why I'm Canceling (and What I'm Using Instead)

https://medium.com/@eliotdill/i-signed-up-for-claude-pro-why-im-canceling-already-and-what-i-m-us...
7•DillyDally125•35m ago•2 comments

Show HN: OpenLayer – local Photoshop plugin for ComfyUI (inpaint/outpaint demo)

https://github.com/MehranMarxian/OpenLayer
4•HMUSER•37m ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.