frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Composer 2.5

https://cursor.com/blog/composer-2-5
1•meetpateltech•36s ago•0 comments

AI Eats The World – Benedict Evans macro trends in tech

https://www.ben-evans.com/presentations
1•nilen•41s ago•0 comments

We Hacked Our Way to Free 4.0s and Took over a UWaterloo and UofT Grading Tool

https://xtra.sh/blog/markus/
1•xtra1•1m ago•0 comments

Email belongs on YOUR disk, not a cloud server

https://mailvaulty.com
1•khaledsabae•1m ago•0 comments

US countertop workers could have damaged lungs, safety expert says

https://www.npr.org/2026/05/18/nx-s1-5691570/silicosis-beyond-california-quartz-countertop-cambria
1•mikhael•1m ago•0 comments

Amiga 68000 (SEKA) → portable C transpiler

https://bitbucket.org/rhinoid/convert68000toc/src/main/
1•ibobev•4m ago•0 comments

Lawyers in Brazil caught for prompt injection on a legal case

https://www.jota.info/trabalho/juiz-multa-em-r-84-mil-advogadas-por-prompt-injection-para-manipul...
1•cfontes•4m ago•0 comments

The Thing Protecting You Is Now the Target

https://thetechvillain.substack.com/p/the-thing-protecting-you-is-now-the
1•interrupt86•6m ago•0 comments

MinusPod self-hosted podcast ad remover learns from opt-in crowdsourced patterns

https://github.com/ttlequals0/MinusPod/blob/main/patterns/README.md
1•Ttlequals0•6m ago•0 comments

DevRel Is So Back

https://scalingdevtools.com/podcast/episodes/scaling-devtools-episode-swyx-final-2-mp4
1•AnhTho_FR•6m ago•0 comments

Encoding the Constitution: Hardcoding Accountability into the Stack

https://brewhubsystems.com/
1•tomc267•7m ago•0 comments

London Erupts Brits Want Their Country Back [video][24 Mins]

https://www.youtube.com/watch?v=pup5aaZ0FAA
1•Bender•8m ago•0 comments

Smallcode – AI coding agent optimized for small LLMs

https://github.com/Doorman11991/smallcode
2•wrxd•9m ago•0 comments

Dutch cops' shame game works wonders as most wanted scammers now turned in

https://www.theregister.com/cyber-crime/2026/05/18/dutch-cops-shame-games-nets-74-wanted-fraudste...
1•darkwater•11m ago•0 comments

Greatest Investor You've Never Heard Of: Optometrist Became Billionaire

https://www.forbes.com/sites/maddieberg/2019/02/19/the-greatest-investor-youve-never-heard-of-an-...
1•rhollos•11m ago•0 comments

Tools for thought: science, design, art, craftsmanship?

https://andymatuschak.org/sdac/
1•Michelangelo11•11m ago•0 comments

Testing Go CLIs with Testscript

https://rednafi.com/go/testscript-cli/
1•Brajeshwar•12m ago•0 comments

Nobel Prize-winning author Olga Tokarczuk admits to using AI

https://old.reddit.com/r/literature/comments/1tgpnfr/nobel_prizewinning_author_olga_tokarczuk_adm...
2•theanonymousone•13m ago•1 comments

Singapore: The Agentic Nation

https://www.swyx.io/aie-singapore-the-agentic-nation
1•Rafsark•13m ago•0 comments

Show HN: Agline – a secure line between local and remote Codex agents

https://agline.dev
1•mariobertschler•14m ago•0 comments

Building Software Requires Digestion

https://blog.jim-nielsen.com/2026/software-requires-digestion/
1•abnercoimbre•15m ago•0 comments

Amazon's Alexa+ Now Produces AI-Generated 'Podcasts'

https://variety.com/2026/digital/news/amazon-alexa-plus-ai-podcasts-1236752477/
1•_____k•16m ago•0 comments

Litter Boxed, an open-source variant of NYT's Letter Boxed

https://louisabraham.github.io/litterboxed/
1•Labo333•17m ago•0 comments

Show HN: Replicating Thinking Machines Interaction Model demo for $0.01 [video]

https://www.youtube.com/watch?v=NzKJ-xO-VhE
1•mrkn1•19m ago•0 comments

Everything is seed (founders are all that count)

https://postround.substack.com/p/everything-is-seed
2•herlaw•20m ago•0 comments

Demo in 16 Bytes [video]

https://www.youtube.com/watch?v=MvycyU-kLjg
2•WithinReason•21m ago•0 comments

I built a dating profile auditor after seeing people post their face on Reddit

https://matchshot.app/
1•bretakal•22m ago•0 comments

Studio Platform API for creating projects and templates programmatically

https://grapesjs.com/blog/introducing-studio-platform-api
1•artf•22m ago•0 comments

Qwen 3.7 Preview

https://twitter.com/Alibaba_Qwen/status/2056403591464984753
2•theanonymousone•23m ago•0 comments

AI tool won't fix a broken operating model. It will automate it

https://techlex.net/strategy-before-technology/
1•basket278•24m ago•0 comments