frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

The Three Durable Function Forms

https://jack-vanlightly.com/blog/2025/12/10/the-three-durable-function-forms
1•birdculture•2m ago•0 comments

Why are there both TMP and TEMP environment variables, and which one is right?

https://devblogs.microsoft.com/oldnewthing/20150417-00/?p=44213
1•ankitg12•6m ago•0 comments

Shadcn/UI: A set of beautifully designed components that you can customize

https://github.com/shadcn-ui/ui
1•doener•8m ago•0 comments

Hanami, Dry and ROM are joining as Hanakai

https://hanakai.org/blog/2026/05/01/welcome-to-hanakai
1•makenosound•8m ago•0 comments

Lucide: Open-source icon library with 1600 vector (SVG) files for icons

https://github.com/lucide-icons/lucide
1•doener•9m ago•0 comments

A collection of Tailwind CSS v4.0 utilities for creating beautiful animations

https://github.com/Wombosvideo/tw-animate-css
1•doener•10m ago•0 comments

There is no Shopify for service businesses. Prove me wrong

https://www.indiehackers.com/post/there-is-no-shopify-for-service-businesses-i-keep-waiting-for-s...
1•stangineer•11m ago•0 comments

SKILL.make: Makefile Styled Skill File

https://github.com/Teaonly/SKILL.make
2•teaonly•11m ago•1 comments

Ask HN: What book have you given as a gift?

2•chistev•15m ago•2 comments

Inspiring Female Heavy Equipment Operators in Construction

https://heavydutyjournal.com/female-heavy-equipment-operators-mastering-construction-and-mining-m...
1•thunderbong•22m ago•0 comments

What is Apache Kafka and how does it work?

https://stanislavkozlovski.medium.com/what-is-apache-kafka-and-how-does-it-work-16023aa2efee
3•filipyonov•26m ago•0 comments

How Go Players Disempower Themselves to AI

https://www.lesswrong.com/posts/nR3DkyivzF4ve97oM/how-go-players-disempower-themselves-to-ai
1•cubefox•27m ago•0 comments

I clustered 3,847 public comments on the Santa Ynez offshore EIS

https://www.envirodocket.com/projects/santa-ynez-unit-resumption-eis
1•scarsam•34m ago•0 comments

Watch NASA test its new X-59 jet designed to go faster than the speed of sound

https://www.scientificamerican.com/video/watch-nasa-test-its-new-x-59-jet-designed-to-go-faster-t...
1•beardyw•36m ago•1 comments

SpaceX ISS Docking SIM

https://iss-sim.spacex.com/
2•CubicalOrange•36m ago•0 comments

Show HN: TurnZero – Persistent Expert for LLMs

1•dmilicev2•38m ago•0 comments

Wine 11.8 – Run Windows Applications on Linux, BSD, Solaris and macOS

https://www.winehq.org/announce/11.8
2•neustradamus•41m ago•0 comments

Show HN: Formattery – on-device file converter for iPhone, iPad, and Mac

https://apps.apple.com/es/app/formattery-convertir-archivos/id6759955312
1•alEscarcha•42m ago•0 comments

Ask HN: Should AI agents have their own legal entities?

1•LRG-H•43m ago•3 comments

Show HN: Hollow is an open-sourced self-modifying agentic system

https://github.com/ninjahawk/hollow-agentOS
4•ninjahawk1•46m ago•0 comments

Show HN: Create the right image sizes for social media

https://skills.sh/branding5/social-media-image-sizes/social-media-image-sizes
1•mnewme•46m ago•0 comments

Open source ballistic simulator with NASA SRTM terrain masking (Python/C#)

https://github.com/InsaneInfinity/Balistic
1•insane_infinity•47m ago•0 comments

Show HN: Glacier – A zero-config macOS terminal I vibecoded in Rust

https://github.com/pranjolm/glacier-terminal
1•ArqueNova•1h ago•0 comments

Microsoft Now Recommends 32 GB RAM as a "No Worries" Upgrade for Windows 11

https://www.techpowerup.com/348715/microsoft-now-recommends-32-gb-ram-as-a-no-worries-upgrade-for...
3•SockThief•1h ago•0 comments

I tell about my blog to anyone willing to listen

https://hamatti.org/posts/i-tell-about-my-blog-to-anyone-willing-to-listen/
1•Tomte•1h ago•0 comments

The Java 21 virtual threads and AI hype is half-true

https://old.reddit.com/r/java/comments/1t1fegr/the_java_21_virtual_threads_ai_hype_is_halftrue/
1•Tomte•1h ago•0 comments

Show HN: Agent with its own computer on the cloud

https://pulsarbot.cloud/
1•akshayballal95•1h ago•0 comments

NSA Warned Everyone to Reboot Their Routers

https://www.staysafeonline.org/articles/the-nsa-just-warned-everyone-to-reboot-their-routers-what...
5•saikatsg•1h ago•0 comments

Using Playwright to test my static sites

https://alexwlchan.net/2026/playwright/
1•ingve•1h ago•0 comments

It's a Weird Time to Be Named Claude

https://www.bloomberg.com/news/articles/2026-05-01/claude-ai-is-complicating-life-for-people-name...
3•helsinkiandrew•1h ago•0 comments