frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•7mo ago

Comments

kemotep•7mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

DoorDash launches AI social app for restaurant discovery

https://www.bloomberg.com/news/articles/2025-12-16/doordash-launches-zesty-an-ai-powered-app-for-...
1•dinosor•54s ago•0 comments

It's time to reset our expectations for AI

https://www.technologyreview.com/2025/12/16/1129946/why-its-time-to-reset-our-expectations-for-ai/
1•janandonly•1m ago•0 comments

Measuring AI's capability to accelerate biological research in the wet lab

https://openai.com/index/accelerating-biological-research-in-the-wet-lab/
1•nowflux•1m ago•0 comments

Other people might just not have your problems

https://thingofthings.substack.com/p/other-people-might-just-not-have
1•terryf•1m ago•0 comments

Paramount's $54B Debt Plays a Starring Role in Warner Bid

https://finance.yahoo.com/news/paramount-54-billion-debt-plays-220757864.html
1•indigodaddy•2m ago•0 comments

OpenCode Desktop (Beta)

https://opencode.ai/download
1•Topfi•2m ago•0 comments

Evaluating AI's ability to perform scientific research tasks

https://openai.com/index/frontierscience/
1•nowflux•3m ago•0 comments

Legup.dev – A pre-flight legal sanity check for indie builders shipping apps

https://legup.dev/
1•usernamevasile•3m ago•1 comments

GitHub will begin charging for self-hosted action runners on March 2026

https://github.blog/changelog/2025-12-16-coming-soon-simpler-pricing-and-a-better-experience-for-...
4•nklow•3m ago•0 comments

X-59 3D Printing

https://www.nasa.gov/stem-content/x-59-3d-printing/
1•Jsebast24•3m ago•0 comments

Show HN: Tab Tangle a browser extension to help clean up tab hoarding

1•langarus•4m ago•0 comments

Two APIs Walk into a Browser: FedCM vs. the DC API

https://sphericalcowconsulting.com/2025/12/16/two-apis-walk-into-a-browser/
1•mooreds•9m ago•0 comments

Improved Gemini audio models for powerful voice interactions

https://blog.google/products/gemini/gemini-audio-model-updates/
2•mfiguiere•10m ago•0 comments

Default Blind

https://blog.sbensu.com/posts/default-blind/
1•gmays•10m ago•0 comments

People Are the New Oil

https://convergentthinking.sh/posts/people-are-the-new-oil/
1•karterk•10m ago•0 comments

Adobe Photoshop 1.0 source code now available

https://sixcolors.com/link/2025/12/adobe-photoshop-1-0-source-code-now-available/
3•xngbuilds•11m ago•2 comments

I made the Xkcd impossible app without any words

https://www.danshapiro.com/blog/2025/12/i-made-the-xkcd-impossible-app-without-any-words/
1•danshapiro•12m ago•0 comments

Molmo 2: State-of-the-art video understanding, pointing, and tracking multimodal

https://allenai.org/blog/molmo2
1•maxloh•12m ago•1 comments

Charcoal Gray Women's Clothing: The Quiet Power Color Every Polished Wardrobe

https://fashionablyfifty.substack.com/p/charcoal-gray-womens-clothing-the
1•MaxwellJ•13m ago•0 comments

Show HN: Simple Go iterator-based backoff library

https://github.com/mzattahri/backoff
1•mohamedattahri•13m ago•0 comments

Show HN: Claude Code Tips

https://github.com/ykdojo/claude-code-tips
1•ykdojo•13m ago•0 comments

Show HN: Sports Database as SMS linking experiment

https://fandicapper.com/
1•garywgrimes•14m ago•0 comments

Theory vs. Practice: Why Technical Interviews Go Wrong

https://zhisme.com/articles/theory-vs-practice-why-technical-interviews-go-wrong
1•zhisme•15m ago•0 comments

Ask HN: Do we all just pretend to know / not know what RESTful API means?

1•idontwantthis•16m ago•0 comments

Zenflow: Free desktop AI Orchestration app with multi-agent verification

https://zencoder.ai/zenflow
4•shcheklein•17m ago•0 comments

Santa's Privacy Policy

https://www.santaprivacy.com/
1•nvahalik•18m ago•0 comments

OmniFlow Beta: multi-user AI-agent back end (Azure and Streamlit)

https://github.com/dokuczacz/OmniFlowBeta
1•dokuczacz•20m ago•1 comments

Geothermal Planning Tools?

1•morpheos137•20m ago•0 comments

FVWM-95

https://fvwm95.sourceforge.net/
27•mghackerlady•23m ago•5 comments

The Year in Computer Science

https://www.quantamagazine.org/the-year-in-computer-science-20251216/
1•baruchel•23m ago•0 comments