frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

The birthday paradox explains why there's too much to do

https://maximumreverie.substack.com/p/why-theres-too-much-to-do
1•kadavy•1m ago•0 comments

Shortcat: Universal command palette for your Mac

https://shortcat.app/
1•gurjeet•2m ago•0 comments

Mysterious Next-Gen Aircraft Allegedly Spotted Near Area 51

https://theaviationist.com/2026/06/04/mysterious-next-gen-aircraft-allegedly-spotted-near-area-51/
1•jawiggins•3m ago•0 comments

One attribute to rule them all

https://www.mapbox.com/blog/one-attribute-to-rule-them-all
1•onesvenus•5m ago•0 comments

Trying to fill up "that one (lonely) moment"

https://mindfuse.io
1•Joeribon•6m ago•0 comments

Connecting the Pieces: AI, Data Centers, and the Environment

https://hitikadalwadi.substack.com/p/connecting-the-pieces-ai-data-centers
1•HitikaDalwadi•7m ago•0 comments

Economic efficiency often undermines sociopolitical autonomy

https://www.mindthefuture.info/p/economic-efficiency-often-undermines
1•paulpauper•8m ago•0 comments

A proposal for an experiment on Scott Alexander's book review contest

https://philosophybear.substack.com/p/what-if-self-promotion-didnt-matter
1•paulpauper•9m ago•0 comments

Choose Book Review Finalists 2026

https://www.astralcodexten.com/p/choose-book-review-finalists-2026
1•paulpauper•9m ago•0 comments

Microsoft Compromised Again Shuts Down Azure Function GitHub Actions

https://opensourcemalware.com/blog/miasma-reaches-azure
2•6mile•10m ago•1 comments

FeckBills – Find the money you're leaking in the cloud

https://feckbills.com/
1•SteveChurch•10m ago•0 comments

KubeTable – your Kubernetes databases, one click away

https://github.com/kubetable/kubetable
1•emmaera•23m ago•1 comments

AI is fueling Reddit's spam problem

https://mashable.com/tech/ai-fueling-reddit-spam-problem
5•mmarian•25m ago•0 comments

Tribute to Jiro Yamada, Automotive Artist (1960-2025) [video]

https://www.youtube.com/watch?v=rJ2gQ5Md60U
3•NaOH•26m ago•0 comments

Before You Add an MCP Server to Your IDE, Read the Config

https://medium.com/open-ai/before-you-add-an-mcp-server-to-your-ide-read-the-config-like-it-can-e...
2•sukhpinder0804•28m ago•0 comments

Donald Trump says US may take equity stakes in AI companies

https://www.ft.com/content/b1ab6106-77e6-4218-9eb4-e44bd56ca400
13•root-parent•35m ago•4 comments

AI Agents Now Generate More Web Traffic Than Humans

https://www.cnet.com/tech/services-and-software/its-official-agentic-bots-surf-the-web-more-than-...
3•Fake4d•37m ago•0 comments

OpenAI wrote a guide on how to use /goal mode. I made that guide into a skill

https://github.com/Infinite-Labs-OS/infinite-skills
1•RiverXR•37m ago•0 comments

OpenAI Codex Tech Lead Does AI-Assisted Engineering

https://newsletter.eng-leadership.com/p/how-openai-codex-tech-lead-does-ai
1•gregorojstersek•39m ago•0 comments

Voyd Programming Language v0.2.0 – Effect typing improvements, trailing closures

https://voyd.dev/docs/?p=releases
1•drew-y•39m ago•0 comments

P/E Tells You the Price. Reality Gap Tells You the Delusion

https://hstre.github.io/Reality-Gap/
3•hstrex•40m ago•0 comments

Morgan Stanley Sees SpaceX's Revenue Reaching $3.4T in 2040

https://www.wsj.com/finance/banking/morgan-stanley-sees-spacexs-revenue-reaching-3-4-trillion-in-...
3•logicalfails•40m ago•3 comments

Hacker News, Sans AI

https://elijahpotter.dev/articles/hacker-news-sans-AI
12•chilipepperhott•40m ago•2 comments

We built an AI sales agent so you don't have to give every demo of your product

https://salescloser.ai/hybrid-chat-va/
1•jrda•40m ago•4 comments

Saylor's Strategy Sells Bitcoin for First Time Since 2022

https://www.wsj.com/finance/currencies/saylors-strategy-sells-bitcoin-for-first-time-since-2022-0...
1•JumpCrisscross•41m ago•0 comments

Playwright for Godot

https://github.com/mrf/godot-stagehand
1•markferree•42m ago•1 comments

Meta backs off tracking workers' keystrokes after they revolt

https://boingboing.net/2026/06/03/meta-backs-off-tracking-workers-keystrokes-after-they-revolt.html
6•DropDead•42m ago•2 comments

Scale Kubernetes deployments to zero using KEDA

https://mijndertstuij.nl/posts/scale-to-zero-keda-cron-scaler/
1•speckx•53m ago•0 comments

Open Source, Co-Ops and a History of Bias in Corporate America

https://radicaltherapy.substack.com/p/open-source-co-ops-and-a-history
3•glind72•53m ago•0 comments

Department of Energy Celebrates First Advanced Reactor Criticality

https://www.energy.gov/articles/department-energy-celebrates-first-advanced-reactor-criticality
1•geox•56m ago•0 comments