frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

RhinoCollab a plugin for real-time editing for Rhino 3D

https://rhinocollab.com
1•Ashxius•11m ago•0 comments

The APLR(1) algorithm for compact LR(1) parsers is simpler and more capable than

https://branchtaken.com/reports/aplr1/aplr1
3•fanf2•12m ago•0 comments

Compiling Isn't Running: Functionally Testing DuckDB-WASM Extensions

https://rusty.today/blog/testing-duckdb-wasm-extensions/
1•rustyconover•16m ago•0 comments

Show HN: AI Cell Enrichment Workflow API

https://ampledata.io
1•blagoysimandoff•18m ago•0 comments

Grasping Exponentialism, Efficient AI, Talent Density, & the Pursuit of Together

https://www.implications.com/p/grasping-exponentialism-efficient
1•momentmaker•19m ago•0 comments

Smaller Code, Better Code

https://www.sacrideo.us/smaller-code-better-code/
2•tosh•22m ago•0 comments

The University in the AI Era

https://htmx.org/essays/universities-and-ai/
1•_doctor_love•25m ago•0 comments

Show HN: Folent – interpolate text between different font typefaces

https://mabugis.github.io/Folent/
1•mabugis•25m ago•0 comments

Agents as Code

https://destiner.io/blog/post/agents-as-code/
1•Destiner•25m ago•0 comments

Section 702 lapsed for the first time since 2008

https://www.axios.com/2026/06/14/trump-fisa-renewal-save-america-act
2•Arodex•26m ago•1 comments

Show HN: Tool for creating step-by-step tutorials from screen recordings. No AI

https://framepin.com/
3•aksuta•27m ago•0 comments

Condom-maker is getting squeezed

https://www.economist.com/business/2026/05/27/the-worlds-top-condom-maker-is-getting-squeezed
1•andsoitis•28m ago•0 comments

A thousand Postgres branches for $1

https://xata.io/blog/a-thousand-postgres-branches-for-1
1•tudorg•29m ago•0 comments

The Sign-Off Layer Is Becoming the Real Engineering System

https://newsletter.thelongcommit.com/p/the-sign-off-layer-is-becoming-the
2•jason_s•35m ago•0 comments

AI is code – and can't be prompted into being smarter

https://www.theregister.com/ai-and-ml/2026/06/14/ai-is-code-and-cant-be-prompted-into-being-smart...
2•wglb•36m ago•0 comments

Why Linux Still Feels Unstable

https://www.whileforloop.com/blog/2026/06/14/why-linux-still-feels-unstable/
2•wook__•38m ago•1 comments

Holy Git! Microsoft code-sharing site suffers downtime, despite move to Azure

https://www.theregister.com/software/2026/06/12/github-outages-persist-as-ai-coding-drives-traffi...
2•Bender•38m ago•0 comments

NHS patients can't opt out of Palantir's data platform – but their hospital can

https://www.theregister.com/databases/2026/06/13/nhs-patients-cant-opt-out-of-palantirs-data-plat...
2•Bender•39m ago•0 comments

Federal Network Agency vs. Steam: Investigation into "Plantation Simulator"

https://www.heise.de/en/news/Federal-Network-Agency-vs-Steam-Investigation-into-Plantation-Simula...
1•mschuster91•40m ago•0 comments

The Minecraft community so nostalgia blinded

1•letlearnbasic•40m ago•0 comments

How to Become an AI-Native Software Engineer? What an AI-Native Team Looks Like

https://medium.com/vibecodingpub/how-to-become-an-ai-native-software-engineer-8f4bda05e7dc
2•SaeedZF•41m ago•0 comments

Why pushback is growing against New Jersey's crazy e-bike law

https://electrek.co/2026/06/13/why-pushback-is-growing-against-new-jerseys-crazy-e-bike-law/
2•Bender•41m ago•0 comments

Vibe Coder vs. Software Engineer

https://yusufaytas.com/vibe-coder-vs-software-engineer
14•yusufaytas•41m ago•0 comments

Why can't I type and scroll at the same time?

https://scrollpods.app/blog/why-cant-i-type-and-scroll-at-the-same-time
1•tippa123•41m ago•0 comments

Researchers uncovering ADHD links to other health conditions

https://www.washingtonpost.com/wellness/2026/06/14/adhd-is-linked-chronic-pain-other-health-condi...
1•bookofjoe•44m ago•1 comments

Commanded, Meet EventSourcingDB

https://docs.eventsourcingdb.io/blog/2026/06/15/commanded-meet-eventsourcingdb/
2•goloroden•44m ago•0 comments

The Leading Deepfake Expert No Longer Trusts His Own Eyes

https://www.nytimes.com/2026/06/14/us/ai-deepfake-hany-farid.html
2•nhyun•46m ago•0 comments

How Are You Feelin.today?

https://feelin.today/
4•michalwarda•47m ago•1 comments

Show HN: Ray Hosting – Topology-aware game server orchestrator made from scratch

https://ray-hosting.com/en-US
2•bardhyliis•50m ago•0 comments

Why All the PRs?

https://idiallo.com/blog/why-all-the-prs
1•firefoxd•51m ago•0 comments