frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Are others seeing Google's ReCAPCHA rejecting Firefox users?

2•Animats•4m ago•1 comments

AMD Versal HBM Series (FPGA's with up to 32GB HBM2e)

https://www.amd.com/en/products/adaptive-socs-and-fpgas/versal/hbm-series.html
2•peter_d_sherman•5m ago•0 comments

Google Lyria 3.5 music generation (public preview)

https://blog.google/innovation-and-ai/models-and-research/google-labs/lyria-3-5/
2•thisisauserid•6m ago•0 comments

Show HN: I processed 100k+ LinkedIn posts into open-source Claude Code skills

https://github.com/sergebulaev/linkedin-skills
1•sbulaev•7m ago•0 comments

Language skills stay strong in elderly while other cognitive abilities decline

https://news.mit.edu/2026/language-skills-stay-strong-older-adults-even-while-other-cognitive-abi...
1•gmays•9m ago•0 comments

Rust stabilizes Never type on nightly

https://github.com/rust-lang/goals/issues/653
2•dabinat•9m ago•0 comments

The death of San Francisco's Market Street

https://www.noahpinion.blog/p/the-death-of-market-street
2•A_D_E_P_T•9m ago•0 comments

MapLoud – An operating system for messy, nonlinear thinking

https://www.maploud.com/platform
1•Nic_Maploud•9m ago•0 comments

Top Pentagon official reaffirms Anthropic blacklist despite Lutnick comments

https://www.axios.com/2026/09/03/pentagon-reaffirms-anthropic-blacklist
2•spenvo•9m ago•0 comments

GPT-6 Astra System Card [pdf]

https://deploymentsafety.openai.com/gpt-6-astra/gpt-6-astra.pdf
3•alvis•10m ago•0 comments

THC Edibles Can Affect Driving for Hours, New Research Shows

https://www.nytimes.com/2026/09/01/well/thc-gummies-edibles-driving.html
1•bookofjoe•10m ago•1 comments

Google has released Gemini 3.8 Flash, its fourth Flash model in under four month

https://artificialanalysis.ai/articles/gemini-3-8-flash
1•wertyk•10m ago•0 comments

Globally distributed pre-training across 48 A100s at $0.12 per million tokens

https://www.tplr.ai/publications/blog/introducing-crucible
1•synapz_org•10m ago•0 comments

Show HN: Agentray, a macOS agent whose interface is a folder

1•beshrkayali•11m ago•0 comments

Why do developers continue to write code by hand?

https://orchidfiles.com/why-write-code-by-hand/
1•theorchid•11m ago•0 comments

GPT-6 Astra System Card

https://deploymentsafety.openai.com/gpt-6-astra
13•codergautam•12m ago•1 comments

Before New York City, Norway Had Banned AI in Schools

https://www.euronews.com/next/2026/09/03/before-new-york-city-norway-had-already-banned-ai-in-sch...
3•jethronethro•12m ago•0 comments

I Think LLMs Will Prove to Be Consequential Enterprise Software

https://freddiedeboer.substack.com/p/i-think-llms-will-prove-to-be-consequential
1•paulpauper•12m ago•0 comments

Ask HN: Why is nobody funding Wikipedia with AI based chat with articles

2•jereees•13m ago•0 comments

The Foldable Tractatus

https://foldabletractatus.aethermug.com/
3•Ishiibahn•13m ago•0 comments

Run cloud agents on machines you manage

https://cursor.com/blog/self-hosted-machines
1•eyehurtsme•14m ago•0 comments

How do I justify spending time to create a world in the first place?

https://worldbuilding.stackexchange.com/questions/124317/how-do-i-justify-spending-time-to-create...
1•joebig•14m ago•0 comments

Ottoman-Era Data Visualizations

https://casualarchivist.substack.com/p/poetic-justice
2•samtheDamned•14m ago•0 comments

Lost Bytes at the Crossroads Between User- and Kernel-Level Memory Allocation [pdf]

https://www.ibr.cs.tu-bs.de/vss/Publications/2026/fistanto_26_lost_bytes.pdf
1•matt_d•15m ago•0 comments

Show HN: AIDemo.Video – turn website into a product demo video in one click

https://www.aidemo.video/
1•distartin•15m ago•0 comments

The Externalities of Airports and Immigrants

https://www.betonit.ai/p/the-externalities-of-airports-and
1•paulpauper•15m ago•0 comments

NIXI has killed the "Dot In" domain name

https://www.naavi.org/wp/nixi-has-killed-the-dot-in-domain-name/
2•pkd•16m ago•1 comments

Sourcerer: New version 1.0.15 is available

https://www.sourcererapp.com/
1•dezelin•17m ago•0 comments

It's Not Just Flock. Police Can't Be Trusted with Our Data

https://truthout.org/articles/its-not-just-flock-police-cant-be-trusted-with-our-data/
4•chaps•21m ago•0 comments

Wall Street banks push Big Law to cut fees because of AI

https://www.ft.com/content/5240a6ac-b2e8-4897-a0a4-cbc7fc283bc9
3•paulpauper•22m ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.