frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

We don't need more contributors who aren't programmers to contribute code

https://discourse.llvm.org/t/rfc-llvm-ai-tool-policy-human-in-the-loop/89159
1•pertymcpert•33s ago•0 comments

Ask HN: Looking for an Invite for Lobster.rs

1•willmorrison•2m ago•0 comments

Antibrittle Agents

https://www.southbridge.ai/blog/antibrittle-agents
1•hrishi•2m ago•0 comments

I built a free tool to explore app market data for indie developers and founders

https://appark.ai/
1•xuechen006•7m ago•1 comments

I curated 25GB of video assets so you don't have to use Stock sites

1•BeyondWalk•12m ago•0 comments

You can now submit fraud claims to the IRS online. Before you had to mail a form

https://twitter.com/shl/status/2005621582677622871
1•raybb•15m ago•1 comments

If childhood is half of life, how should that change how we live?

https://moultano.wordpress.com/2025/12/30/children-and-helical-time/
1•moultano•17m ago•0 comments

Play Free Online Games – No Download Needed – MiniTapFun

https://minitapfun.com
2•heihieih•21m ago•0 comments

MTTR-A: Measuring Cognitive Recovery Latency in Multi-Agent Systems

https://arxiv.org/abs/2511.20663
2•PaulHoule•29m ago•0 comments

OpenSSL Performance Still Under Scrutiny

https://www.feistyduck.com/newsletter/issue_132_openssl_performance_still_under_scrutiny
1•todsacerdoti•32m ago•0 comments

L1TF Reloaded

https://github.com/ThijsRay/l1tf_reloaded
3•Fnoord•32m ago•0 comments

I hope generative AI does away with SEO

https://www.pcloadletter.dev/blog/ai-and-seo/
1•ronbenton•33m ago•0 comments

Spectre in the real world: Leaking your private data from cloud with CPU vulns [video]

https://media.ccc.de/v/39c3-spectre-in-the-real-world-leaking-your-private-data-from-the-cloud-wi...
1•Fnoord•34m ago•0 comments

VL-JEPA: Joint Embedding Predictive Architecture for Vision-Language

https://arxiv.org/abs/2512.10942
2•hbarka•40m ago•0 comments

Using AI generated images to get refunds

https://www.wired.com/story/scammers-in-china-are-using-ai-generated-images-to-get-refunds/
1•MattSayar•43m ago•0 comments

Show HN: WizardFlow – Client-side watermarking for Reddit

https://chromewebstore.google.com/detail/wizardflow-image-assistan/hogehefggenldjhcopnpffpgnoepllii
1•jackking1•45m ago•1 comments

Users are required to log in to Bugzilla even to view existing bug reports

https://lists.gnucash.org/pipermail/gnucash-user/2025-September/117417
1•aendruk•45m ago•0 comments

SomaliScan – US Fraud aggregator sourced from public records

https://www.somaliscan.com/
11•sergiotapia•45m ago•1 comments

Show HN: Client-side encrypted AI detector using model ensembling

https://veredictlabs.com
1•oscarzdev•47m ago•0 comments

Effective Alruists Should Embrace Sortition

https://almostinfinite.substack.com/p/effective-altruists-should-embrace
1•maaaaxaxa•48m ago•1 comments

Show HN: Easy Habits

https://habits.easycyberprotection.com/
1•ToJans•55m ago•0 comments

Show HN: Marathon Cope 2025 – Your peak fitness, whether or not you ran it

https://getfast.ai/marathon-cope
3•steadyelk•1h ago•0 comments

The science of how (and when) we decide to speak out–or self-censor

https://arstechnica.com/science/2025/12/the-science-of-how-and-when-we-decide-to-speak-out-or-sel...
2•pseudolus•1h ago•0 comments

MCP to trade Robinhood through Claude Code

https://github.com/trayders/trayd-mcp
2•teamtrayd•1h ago•0 comments

Italy antitrust agency fines Apple $116M over privacy feature

https://apnews.com/article/apple-italy-fine-antitrust-privacy-feature-760715f8985f7cb49392f27daff...
3•1vuio0pswjnm7•1h ago•0 comments

Readings in Database Systems (5th Edition)

http://www.redbook.io/
3•teleforce•1h ago•1 comments

New at the Nursery: Tomato and Potato = TomTato

https://www.theatlantic.com/technology/archive/2013/11/new-at-the-nursery-tomato-potato-tomtato/2...
1•MaysonL•1h ago•2 comments

Show HN: ClearTok – a small tool to remove reposted videos from TikTok

https://cleartok.io/
1•auroroa•1h ago•0 comments

Tech Startups Are Handing Out Free Nicotine Pouches to Boost Productivity

https://www.wsj.com/tech/tech-startups-are-handing-out-free-nicotine-pouches-to-boost-productivit...
4•nradov•1h ago•0 comments

Can AI Recognize Its Own Reflection?

https://arxiv.org/abs/2512.23587
1•StatsAreFun•1h ago•0 comments