frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Nitsum: Serving Tiered LLM Requests with Adaptive Tensor Parallelism

https://mlsys.wuklab.io/posts/nitsum/
1•matt_d•3m ago•0 comments

SuperInfer: SLO-Aware Rotary Scheduling and Memory Management for LLM Inference

https://supercomputing-system-ai-lab.github.io/projects/superinfer/
1•matt_d•4m ago•0 comments

What can a local model do for you in early May 2026?

https://manichord.com/blog/posts/what-can-local-model-do-in-may-2026
2•mkss•7m ago•0 comments

Guess where someone works based on their profile picture

https://tools.crustdata.com/guessthecompany
1•mhi3•11m ago•0 comments

Sony Pulls Back from PlayStation Games on PC

https://www.bloomberg.com/news/articles/2026-03-04/sony-pulls-back-from-playstation-games-on-pc
1•embedding-shape•11m ago•0 comments

Museum of Innocence (Museum)

https://en.wikipedia.org/wiki/The_Museum_of_Innocence_(museum)
1•brudgers•13m ago•0 comments

Video GTP

https://www.neotube.ai/
1•walkervin•16m ago•0 comments

BudgetBites – AI meal planning app that helps you save money on groceries

https://budgetbites.website/login
1•ClarenceJackson•18m ago•0 comments

Make products AI agents want

https://anitakirkovska.com/blog/make-products-ai-agents-want/
1•anitakirkovska•20m ago•0 comments

Google, Blackstone plan AI cloud venture with $5B backing, WSJ reports

https://www.reuters.com/business/google-blackstone-create-new-ai-cloud-company-wsj-reports-2026-0...
1•ndesaulniers•21m ago•0 comments

We should stop using Agile and Waterfall as is

https://quantumentangled.dev/viewpost/12/we-should-stop-using-agile-and-waterfall-asis
1•rulyone•22m ago•0 comments

Feedback on my S&P 500 Search Tool (fast search by name, ticker, sector)

https://sp500-search.streamlit.app/
1•gilthor•29m ago•0 comments

Will the Indus Valley script ever be deciphered?

https://www.livescience.com/archaeology/will-the-indus-valley-script-ever-be-deciphered
1•redwood•30m ago•1 comments

May I recommend eww for Emacs's innovative UI?

https://www.matem.unam.mx/~omar/apropos-emacs.html#may-i-recommend-eww-for-emacs-innovative-ui
1•birdculture•47m ago•0 comments

Climate scientists admit doomsday scenario no longer believable

https://www.gbnews.com/science/apocalypse-forecasts-climate-scientists
5•nxm•51m ago•1 comments

Google and Blackstone to Create New AI Cloud Company

https://www.wsj.com/tech/ai/google-and-blackstone-to-create-new-ai-cloud-company-0e35b91f
4•frays•54m ago•0 comments

Self-Hosted Web Application for Displaying and Interacting with KiCad Projects

https://github.com/krishna-swaroop/KiCAD-Prism
1•djfergus•57m ago•0 comments

An Apple (II) for Teacher

https://technicshistory.com/2026/05/19/an-apple-ii-for-teacher/
1•cfmcdonald•1h ago•0 comments

Five months after switching Fluxzy from Electron to Tauri

https://www.fluxzy.io/resources/blogs/electron-to-tauri-migration-fluxzy-desktop
1•nreece•1h ago•0 comments

Microsoft surprises with its first server Linux distribution: Azure Linux 4.0

https://www.zdnet.com/article/microsoft-releases-its-first-server-linux-distribution-azure-linux-...
10•CrankyBear•1h ago•1 comments

AgentCRM – Headless CRM for Claude Code

https://github.com/cluster-software/agent-crm
3•samuelstros•1h ago•0 comments

Melbourne psychiatrist refuses new patients who don't consent to AI note-taking

https://www.theguardian.com/australia-news/2026/may/19/melbourne-psychiatrist-ai-note-taking-new-...
2•anotherevan•1h ago•0 comments

Data Center Waste Heat as an Emerging Urban Thermal Hazard

https://asmedigitalcollection.asme.org/sustainablebuildings/article/doi/10.1115/1.4071922/1233035...
1•littlexsparkee•1h ago•0 comments

What political censorship looks like inside an LLM's weights (Qwen 3.5)

https://vas-blog.pages.dev/qwen-censorship/
34•s314•1h ago•0 comments

Apple kicks off WWDC on June 8

https://www.apple.com/newsroom/2026/05/apple-kicks-off-worldwide-developers-conference-on-june-8/
1•throw0101c•1h ago•0 comments

Building a hyper modular framework for hardware

https://www.getubo.com/post/building-a-flexible-future-proof-compute-system
1•mmajzoobi•1h ago•1 comments

how coding harnesses are used, an introspection

https://research.tamarillo.ai/coding-harness-inspection/
5•ivanbelenky•1h ago•2 comments

From-scratch reimplementation of Mythos Glasswing pipeline

https://github.com/evilsocket/audit
2•djfergus•1h ago•0 comments

A Simple Image Brightness and Contrast Adjustment Technique

https://geo-ant.github.io/blog/2026/simple-image-contrast-brightness-adjustment/
2•yurivish•1h ago•0 comments

Azure's MFA Warning Links Free-Tier Users to a Page They Can't Use

https://playtechnique.io/blog/azures-mfa-warning.html
1•gwynforthewyn•1h ago•0 comments