frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: I made a quiz to help people learn Claude Code features

https://slashquiz.org/
1•cjbarber•57s ago•0 comments

Collaborative code editor implementation is harder than you expect

https://medium.com/@growth_9158/building-a-reliable-collaborative-code-editor-lessons-from-shippi...
1•tomodachiprep•3m ago•0 comments

Show HN: Stet – PostScript Level 3 interpreter and PDF toolkit in Rust

https://andycappdev.github.io/stet/
1•AndyCappDev•3m ago•0 comments

My University Hired a Terrorist

https://www.facultyleaks.com/p/my-university-hired-terrorist
1•johndcook•3m ago•0 comments

•4m ago

Addressing the Harassment

https://drewdevault.com/blog/Addressing-harassment/
1•Tomte•5m ago•0 comments

Show HN: LemmaScript, a verification toolchain for TypeScript via Dafny

https://github.com/midspiral/LemmaScript
1•namin•5m ago•0 comments

Show HN: GoModel – an open-source AI gateway in Go; 44x lighter than LiteLLM

https://github.com/ENTERPILOT/GOModel/
1•santiago-pl•5m ago•0 comments

The Internet Is Real Life

https://www.a16z.news/p/the-internet-is-real-life
1•7777777phil•6m ago•0 comments

The Oil Shock Is About to Hit America [video][25mins]

https://www.youtube.com/watch?v=f353QO5Dgus
1•Bender•7m ago•0 comments

NASA's Curiosity rover finds organic molecules on Mars

https://www.theguardian.com/science/2026/apr/21/nasa-curiosity-rover-finds-organic-molecules-mars
1•skor•7m ago•0 comments

Return of the Saturday Night Special, Courtesy of the SEC

https://clsbluesky.law.columbia.edu/2026/04/21/return-of-the-saturday-night-special-courtesy-of-t...
1•petethomas•9m ago•0 comments

Request Tracking: Lessons from Card Payments and HTTP/2

https://madflojo.dev/posts/in-flight-request-tracking-in-asynchronous-systems/
1•madflojo•9m ago•0 comments

GitHub has stopped accepting new Copilot individual subscriptions

https://www.theregister.com/2026/04/20/microsofts_github_grounds_copilot_account/
1•Betelbuddy•9m ago•0 comments

A Century of Chaos in a Single Emoji

https://jenniferdaniel.substack.com/p/a-century-of-chaos-in-a-single-emoji
1•ChrisArchitect•9m ago•0 comments

AppWatch – Track Itch.io, Steam, App Store and Google Play in One Dashboard

https://appwatch.dev
1•ranguita•10m ago•2 comments

An LLM invented a feature by hijacking my tool schema

https://ratnotes.substack.com/p/i-thought-i-had-a-bug
1•mtrifonov•10m ago•0 comments

Cocaine pollution alters the movement and space use of Atlantic salmon

https://www.cell.com/current-biology/fulltext/S0960-9822(26)00315-5
1•ajay-d•11m ago•1 comments

Zelensky says failure of US envoys to visit Kyiv is 'disrespectful'

https://www.bbc.com/news/articles/cd9v420y190o
6•Betelbuddy•12m ago•1 comments

Abusing PostHog's setup wizard to get free Claude access

https://techstackups.com/articles/i-abused-posthogs-setup-wizard-to-get-free-claude-access/
1•ritzaco•12m ago•0 comments

Neurobiologists Hack Brain Circuits Tied to Placebo Pain Relief

https://today.ucsd.edu/story/neurobiologists-hack-brain-circuits-tied-to-placebo-pain-relief
1•gmays•12m ago•0 comments

AES 128 is just fine in a post-quantum world

https://arstechnica.com/security/2026/04/contrary-to-popular-superstition-aes-128-is-just-fine-in...
1•mmwelt•12m ago•0 comments

The Kuleshov Effect

https://en.wikipedia.org/wiki/Kuleshov_effect
1•janandonly•13m ago•0 comments

The Forgotten History of Hershey's Electric Railway (1916) in Cuba

https://spectrum.ieee.org/hershey-electric-railway-cuba
1•defrost•14m ago•0 comments

Design isn't dying. It's shifting left

https://microsoft.design/articles/design-isnt-dying-its-shifting-left/
1•djurgardensif•14m ago•0 comments

Agentic memory with passive recall and citations as trust graph

https://github.com/Kromatic-Innovation/athenaeum
1•TristanKromer•14m ago•1 comments

Russia Is Building Tomorrow's War Machine

https://www.nytimes.com/2026/04/21/opinion/russia-drones-putin-ukraine-war.html
2•mitchbob•15m ago•1 comments

Artemis II Watches Earth Set Behind the Moon [video]

https://www.youtube.com/shorts/MT8tg5b3b8E
1•bookofjoe•16m ago•0 comments

Curiosity rover finds signs of ancient life on Mars

https://www.popsci.com/science/curiosity-rover-life-mars/
1•Brajeshwar•19m ago•0 comments

Increased AI expectations without guidance leads to employee burnout

https://www.cio.com/article/4159631/increased-ai-expectations-without-guidance-leads-to-employee-...
2•WaitWaitWha•19m ago•0 comments