frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Partitioning a 17TB Table in PostgreSQL

https://www.tines.com/blog/futureproofing-tines-partitioning-a-17tb-table-in-postgresql/
1•shayonj•39s ago•0 comments

VS Code: Broken rendering on macOS after app resumed from idle state

https://github.com/microsoft/vscode/issues/284162
1•tosh•1m ago•0 comments

OpenAI Wants a Cut of Your Profits: Inside Its New Royalty-Based Plan

https://www.gizmochina.com/2026/01/21/openai-wants-a-cut-of-your-profits-inside-its-new-royalty-b...
1•thenaturalist•1m ago•0 comments

Shenzhou-20 Returns Safely After Historic In-Flight Debris Repairs

https://www.apollothirteen.com/article/orbital-resilience-shenzhou-20-returns-safely-following-hi...
1•darkmatternews•2m ago•0 comments

Alternatives to MinIO for single-node local S3

https://rmoff.net/2026/01/14/alternatives-to-minio-for-single-node-local-s3/
1•rymurr•3m ago•0 comments

Show HN: A verified foundation of mathematics in Coq (Theory of Systems)

1•Horsocrates•5m ago•0 comments

Heathrow's new scanners end dreaded rummage for liquids and laptops

https://www.reuters.com/world/heathrows-new-scanners-end-dreaded-rummage-liquids-laptops-2026-01-23/
1•comebhack•7m ago•0 comments

Can the prescription drug leucovorin treat autism? History says, probably not

https://www.npr.org/sections/shots-health-news/2026/01/22/nx-s1-5684294/leucovorin-autism-folic-f...
1•pseudolus•15m ago•0 comments

Davos Stops Pretending

https://messaging-custom-newsletters.nytimes.com/dynamic/render
1•doener•15m ago•0 comments

For the Children: A short story about the endgame of EU Chat Control

https://gigaprojects.online/post/1
1•giga_private•17m ago•1 comments

An Adversarial Coding Test

https://runjak.codes/posts/2026-01-21-adversarial-coding-test/
1•birdculture•18m ago•0 comments

Go Developer Survey 2025: How Gophers Use AI Tools, Editors, and Cloud Platforms

https://go.dev/blog/survey2025
1•Lwrless•18m ago•0 comments

Ask HN: What's the current best local/open speech-to-speech setup?

1•dsrtslnd23•21m ago•0 comments

A Multi-Entry Control Flow Graph Design Conundrum

https://bernsteinbear.com/blog/multiple-entry/
1•chunkles•23m ago•0 comments

Bernstein vs. United States

https://en.wikipedia.org/wiki/Bernstein_v._United_States
1•u1hcw9nx•25m ago•0 comments

Show HN: Workmux – Parallel development in tmux with Git worktrees

https://workmux.raine.dev/
1•rane•26m ago•0 comments

Show HN: 9 years building an open-source financial platform

https://github.com/finmars-platform/finmars-core
2•ogreshnev•26m ago•0 comments

Ask HN: What 'AI feature' created negative ROI in production?

1•kajolshah_bt•27m ago•0 comments

TigerBeetle's Stablecoin Mistake

https://www.news.alvaroduran.com/tigerbeetle-stablecoin-mistake/
1•ohduran•27m ago•0 comments

What Will You Do When AI runs Out of Money and Disappear?

https://louwrentius.com/what-will-you-do-when-ai-will-run-out-of-money-and-disappear.html
1•louwrentius•30m ago•0 comments

Why is software still built like billions don't exist in 2026?

5•yerushalayim•31m ago•2 comments

Is Polish Scrabble the most difficult in the world? [video]

https://www.youtube.com/watch?v=aTIOHwT0FnY
1•nathell•32m ago•0 comments

Post-Agentic Code Forges

https://sluongng.substack.com/p/post-agentic-code-forges
1•todsacerdoti•32m ago•0 comments

In-memory analog computing for non-negative matrix factorization

https://www.nature.com/articles/s41467-026-68609-8
1•martinlaz•37m ago•0 comments

RT Superconductivity at 298K in Ternary LaScH System at High-Pressure Conditions

https://arxiv.org/abs/2510.01273
1•fluffybuns•39m ago•0 comments

Show HN: Waifu2x.live – Free AI image upscaler (2x/4x) & video generation

1•Nancy1230•39m ago•1 comments

Campaigner launches £1.5B legal action in UK against Apple over wallet's ...

https://www.theguardian.com/technology/2026/jan/23/campaigner-launches-legal-action-against-apple...
1•chrisjj•42m ago•1 comments

Anthropic: AI Is Transforming Jobs, Not Replacing Them

https://www.forbes.com/sites/anishasircar/2026/01/23/ai-is-transforming-jobs-not-replacing-them-a...
1•hochmartinez•42m ago•1 comments

AI Boosts Research Careers but Flattens Scientific Discovery

https://spectrum.ieee.org/ai-science-research-flattens-discovery
1•pseudolus•42m ago•0 comments

Google must face consumer antitrust lawsuit over search dominance,US judge rules

https://www.reuters.com/legal/government/google-must-face-consumer-antitrust-lawsuit-over-search-...
2•pseudolus•44m ago•0 comments