frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

A defunct email service as a template for campus AI

https://nathanschneider.info/2026/05/a-defunct-email-service-as-a-template-for-campus-ai/
1•ntnsndr•3m ago•0 comments

Why should a Trace-ID be 128 bits?

https://newsletter.signoz.io/p/why-should-a-trace-id-be-128-bits
1•pranay01•4m ago•0 comments

Dmitry Senin - I escaped Vladimir Putin in the belly of a dead cow

https://www.telegraph.co.uk/world-news/2026/05/14/dmitry-senin-russia-fsb-escaped-putin-in-dead-cow/
1•canucker2016•7m ago•0 comments

reCAPTCHA Mobile Verification Is Bringing the Play Integrity API to Desktops

https://discuss.grapheneos.org/d/35428-recaptcha-mobile-verification-is-bringing-the-play-integri...
2•Cider9986•8m ago•0 comments

Ask HN: What is shared across participants within "AI-native" environments?

1•juun_roh•12m ago•0 comments

Wide-Band Subharmonic Modeling

https://queuesevenm.wordpress.com/2026/05/14/wide-band-subharmonic-modeling/
1•q7m•17m ago•0 comments

Browser HTTP Leak Test

https://raw.githubusercontent.com/cure53/HTTPLeaks/main/leak.html
1•1vuio0pswjnm7•19m ago•0 comments

What if websites were callable like APIs?

https://github.com/weekend-project-space/openwalk
2•zhugeyangyang•19m ago•1 comments

We're Building Neal Stephenson's Primer

https://github.com/hherb/primer
1•hherb•21m ago•1 comments

Mullvad exit IPs are surprisingly identifying

https://tmctmt.com/posts/mullvad-exit-ips-as-a-fingerprinting-vector/
5•RGBCube•25m ago•0 comments

Explore PPP Loans on an interactive map

https://www.ppploanmap.com/
2•zarie•25m ago•0 comments

Laid-off Oracle workers tried to negotiate better severance. Oracle said no

https://techcrunch.com/2026/05/08/laid-off-oracle-workers-tried-to-negotiate-better-severance-ora...
1•dskrvk•26m ago•0 comments

Switch to Codex

https://chatgpt.com/codex/switch-to-codex/
5•dragonsenseiguy•30m ago•1 comments

AI co-mathematician: Accelerating mathematicians with agentic AI

https://arxiv.org/abs/2605.06651
1•aoki•38m ago•0 comments

The Efficiency Moat: Why China Is Beating the U.S. on AI and Everything Else

https://www.thebignewsletter.com/p/the-efficiency-moat-why-china-is
4•connor11528•43m ago•0 comments

AI music generator so YouTubers never get copyright strikes

https://dmitrithegamer.github.io/soundcraft/
1•soundcraftai•49m ago•0 comments

LLMs can't read PDFs in 2026?

https://musings-mr.net/post/where-state-of-the-art-fails
2•mrkiouak•51m ago•1 comments

WordPress Lost 19% of the Internet to AI [video]

https://www.youtube.com/watch?v=0tFRdZWmGdc
1•mgh2•54m ago•0 comments

Agentic Search Models

https://softwaredoug.com/blog/2026/05/11/the-new-agentic-search-models.html
1•gmays•55m ago•0 comments

Gargoyle, a Decade Later

https://lospino.so/blog/gargoyle-a-decade-later/
1•jalospinoso•56m ago•0 comments

Big Shot On The East Coast: The History of the Zoo York Mixtape

https://daily.redbullmusicacademy.com/2013/07/zoo-york-mixtape-feature/
1•marysminefnuf•58m ago•0 comments

Monero's Biggest Privacy Upgrade Is Almost Here: Justin Berman on FCMP Stressnet

https://youtube.com/M2rbsjTSFt8?t=52
1•Cider9986•1h ago•1 comments

GPT convinced me there was a bug in my code before a freeze

https://www.droppedasbaby.com/posts/2602-02/
1•offbyone42•1h ago•0 comments

I resurrected the web from the past and it got weird

https://slopcities.com/
3•ZenBlender•1h ago•1 comments

Bumble Is Removing the Swipe Feature, Will Use AI in New Launch

https://www.eonline.com/news/1431973/bumble-removing-swipe-feature-will-use-ai-in-new-launch
1•mgh2•1h ago•0 comments

Find vendors used by any company

https://sub-processors.com/subprocessor/elasticsearch
2•chatmasta•1h ago•0 comments

Ask HN: When will you be concerned on layoffs?

4•piratesAndSons•1h ago•0 comments

Restartable Sequences, TCMalloc, and Hyrum's Law

https://lwn.net/Articles/1070072/
1•signa11•1h ago•0 comments

Caltrans Explores High-Speed Bus Network to Complement Rail System

https://www.kqed.org/news/12083467/caltrans-explores-high-speed-buses-as-alternative-to-rail-in-c...
3•rawgabbit•1h ago•1 comments

Popular node-ipc NPM Package Infected with Credential Stealer

https://socket.dev/blog/node-ipc-package-compromised
1•csmantle•1h ago•0 comments