frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Canvas hack: Company pays criminals to delete students' stolen data

https://www.bbc.com/news/articles/cdepzg83x87o
1•smurda•12s ago•0 comments

Compressing Scrabble Dictionaries (2014)

https://williame.github.io/post/87682811573.html
1•kristianp•1m ago•0 comments

Compared to What? Baselines and Metrics for Counterfactual Prompting

https://arxiv.org/abs/2605.01048
1•Anon84•1m ago•0 comments

Zoom info charges 15k a year for business leads. I built an alternative using AI

https://dayonelead.com
2•monkeeguy•2m ago•0 comments

Foxconn confirms cyberattack after Nitrogen claims Apple, Nvidia data theft

https://www.theregister.com/cyber-crime/2026/05/12/foxconn-confirms-cyberattack-after-nitrogen-cl...
1•y1n0•6m ago•0 comments

When "idle" isn't idle: how a Linux kernel optimization became a QUIC bug

https://blog.cloudflare.com/quic-death-spiral-fix/
1•sbulaev•7m ago•0 comments

Scaling MCP adoption: Our ref architecture – simpler,safer&cheaper deployments

https://blog.cloudflare.com/enterprise-mcp/
1•Daviey•8m ago•0 comments

What the Heck Is Reflection?

https://www.murathepeyiler.com/what-the-heck-is-reflection/
1•HeliumHydride•8m ago•0 comments

Tesla moves Basic Autopilot features to paid FSD where available

https://electrek.co/2026/05/12/tesla-removes-basic-autopilot-netherlands-fsd-only/
1•y1n0•10m ago•0 comments

Mini Shai-Hulud Is Back: NPM Worm Hits over 160 Packages, Including Mistral

https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised
1•cebert•10m ago•1 comments

The Silence That Meets the Rape of Palestinians

https://www.nytimes.com/2026/05/11/opinion/israel-palestinians-sexual-violence.html
3•Zaheer•11m ago•0 comments

Anthropic in Talks to Raise Funding at a $950B Valuation

https://www.nytimes.com/2026/05/12/technology/anthropic-funding-950-billion-valuation.html
2•y1n0•13m ago•0 comments

Mythos for Offensive Security: XBOW's Evaluation

https://xbow.com/blog/mythos-offensive-security-xbow-evaluation
1•tedsanders•16m ago•0 comments

Show HN: Display.dev, agent-native way to publish HTML or MD behind company auth

https://display.dev/
1•CarlRannaberg•18m ago•0 comments

World Record Solver for Minimum Line Cover of Prime Points Cuts Time to 22

https://prime-line-cover.vercel.app/?article
1•birdculture•19m ago•0 comments

Fluxspeak – make people sound human while reading

https://github.com/skorotkiewicz/freeflow/tree/main/fluxspeak
1•modinfo•22m ago•0 comments

Show HN: Rs-pug – A scriptable terminal music player written in Rust with Lua

https://github.com/JustRoccat/rs-pug
1•coldbrxthe•23m ago•0 comments

AI load breaks GitHub – why not other vendors?

https://blog.pragmaticengineer.com/the-pulse-ai-load-breaks-github/
4•esafak•26m ago•1 comments

Lukashenko Says Belarus Is Preparing for War, Plans to "Mobilize Units"

https://united24media.com/world/lukashenko-says-belarus-is-preparing-for-war-plans-to-mobilize-un...
2•arpadav•34m ago•0 comments

Android 17 will soon tell you whether your OS is legit

https://www.androidauthority.com/android-17-os-verification-3665868/
2•gumby271•36m ago•0 comments

The Cost of Doing Business: How SF's Tax Structure Constrains Economic Growth [pdf]

https://www.bayareaeconomy.org/files/pdf/CostofDoingBusiness_TaxStudy_May2026.pdf
2•littlexsparkee•37m ago•1 comments

In the Vacuum of AI Legislation, Libraries Have the Playbook

https://www.techdirt.com/2026/05/11/in-the-vacuum-of-ai-legislation-libraries-have-the-playbook/
2•hn_acker•40m ago•0 comments

Kraftwerk's radical 1976 track

https://www.bbc.com/culture/article/20260511-kraftwerks-radical-1976-track-radioactivity-became-a...
19•tcp_handshaker•41m ago•0 comments

Clusters become personal (like PCs did)

https://aranya.tech/blog/arrival-of-the-personal-cluster
2•druid•42m ago•0 comments

Tell NYT, Atlantic, USA Today to Keep Wayback Machine

https://www.savethearchive.com/newsleaders/
2•doener•42m ago•1 comments

Musk said control of OpenAI should go to his children, Sam Altman tells jury

https://www.bbc.com/news/articles/czj2k2exdzlo
2•tcp_handshaker•42m ago•0 comments

A Remarkably Luminous Galaxy at Zspec = 14.44 Confirmed with JWST

https://arxiv.org/abs/2505.11263
2•tcp_handshaker•45m ago•1 comments

Scientists Confirm 'Brain-Eating Amoeba' Is Widespread Yellowstone Grand Teton

https://cowboystatedaily.com/2026/05/12/scientists-confirm-brain-eating-amoeba-is-widespread-in-y...
3•Bender•45m ago•0 comments

What We Think About When We Think About Benchmarking

https://www.paradedb.com/blog/what-we-think-about-when-we-think-about-benchmarking
1•jamesgresql•46m ago•1 comments

FDA chief resigns after Trump admin forced approval of fruity e-cigs

https://arstechnica.com/health/2026/05/fda-chief-resigns-after-trump-admin-forced-approval-of-fru...
6•Bender•47m ago•1 comments