frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

The Zechner-Lopopolo Continuum: Do you even read your Clanker code? Should you?

https://sub.thursdai.news/p/the-lopopolo-zechner-spectrum
1•altryne1•10s ago•1 comments

Reposit: Collective Intelligence for AI Agents

https://reposit.bot/
1•gtirloni•3m ago•0 comments

Claude Major Outage

https://status.claude.com/history
2•flyaway123•3m ago•1 comments

Building a CLI for All of Cloudflare

https://blog.cloudflare.com/cf-cli-local-explorer/
2•soheilpro•3m ago•0 comments

1 in 30 – Artemis, Greatness, and Risk

https://1517.substack.com/p/1-in-30-artemis-greatness-and-risk
1•gmays•4m ago•0 comments

Ask HN: What makes it so hard to keep LLMs online?

2•realberkeaslan•4m ago•0 comments

DataLink APIs – unified email, phone, IP and domain Intel under one API key

https://www.datalinkapis.com/
1•imtiaznoor•4m ago•0 comments

Ask HN: Is Claude Down Again?

3•rreyes1979•4m ago•1 comments

Stealthy RCE on Hardened Linux: Noexec and Userland Execution PoC

https://hardenedlinux.org/blog/2026-04-13-stealthy-rce-on-hardened-linux-noexec--userland-executi...
2•hardenedlinux•5m ago•0 comments

Claude.ai down

https://status.claude.com/incidents/6jd2m42f8mld
22•rob•6m ago•6 comments

Tell HN: Claude Opus elevated "Internal server error" again

3•StanAngeloff•7m ago•1 comments

Tell HN: Another Monday, Another Claude Outage

4•ericol•7m ago•1 comments

Tell HN: Claude Code Is Down

7•Nevin1901•8m ago•2 comments

I ran Gemma 4 as a local model in Codex CLI

https://medium.com/google-cloud/i-ran-gemma-4-as-a-local-model-in-codex-cli-7fda754dc0d4
1•vasinov•8m ago•0 comments

Emperor penguin, Antarctic fur seal now listed as endangered in IUCN Red List

https://abcnews.com/US/emperor-penguin-antarctic-fur-seal-now-listed-endangered/story?id=131546391
1•gmays•8m ago•0 comments

ClearFrame – Secure Auditable Alternative to OpenClaw

https://github.com/ibrahimmukherjee-boop/ClearFrame
1•ibrahim23456•9m ago•0 comments

Hey Claude, print recent AI news, short

https://ai-tldr.dev/
3•dralexturner•9m ago•0 comments

A New SQLite Parser

https://marcobambini.substack.com/p/liteparser-a-fast-embeddable-sqlite
1•marcobambini•9m ago•0 comments

I built an API for AI agents that handles phone numbers, SMS, OTP and voice

https://agentcall.co
1•kintupercy•9m ago•1 comments

Show HN: Behavioural-dashboard, framework agnostic library for living dashboards

https://ricardomonteirosimoes.github.io/behavioural-dashboard/
1•RicDan•11m ago•0 comments

Developer skills post-AI: TDD, context engineering, metrics, ownership?

https://nguyengineer.dev/developers-what-should-we-do-next-in-the-age-of-ai
1•finn319•11m ago•0 comments

Algebrica – A Mathematical Knowledge Base

https://algebrica.org/
1•marklit•11m ago•1 comments

Open Source Mystery: 3.5M downloads, But what are people using this for?

https://minifetch.com
1•eljee•11m ago•1 comments

Nineteen Features, Zero Architecture

https://fffej.substack.com/p/nineteen-features-zero-architecture
2•mooreds•12m ago•0 comments

Servo Browser Engine Making It Easier for Embedded Use

https://www.phoronix.com/news/Servo-Embed-Crates-LTS
1•Brajeshwar•12m ago•0 comments

How to make Dropbox ignore the node_modules folder

https://evanxmerz.com/post/how-to-tell-dropbox-to-ignore-node-modules/
1•bariumbitmap•14m ago•0 comments

Destroying Communication and Control in Software Development (2003) [pdf]

https://www.ayeconference.com/Articles/weinberg.pdf
1•rzk•15m ago•0 comments

Can astrologers gain insights about people from astrological charts?

https://www.clearerthinking.org/post/can-astrologers-use-astrological-charts-to-understand-people...
1•pelf•15m ago•0 comments

The AI divide putting open weights models in spotlight

https://www.theregister.com/2026/04/12/ai_open_weights_models/
2•tanelpoder•16m ago•0 comments

500 Tbps of capacity: 16 years of scaling our global network

https://blog.cloudflare.com/500-tbps-of-capacity/
3•sp8•16m ago•0 comments