frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Microsoft CTO: Why the OpenAI Board Fired Sam Altman

https://twitter.com/TechEmails/status/2018034985563996291
1•typeofhuman•28s ago•0 comments

Show HN: I turned my PDFs into audiobooks I can have conversations with

https://asktotle.com
1•simpnoza•2m ago•0 comments

How Tailscale is improving NAT traversal (Part 1)

https://tailscale.com/blog/nat-traversal-improvements-pt-1
1•rzk•3m ago•0 comments

Making physical Japanese cards: The full walkthrough from zero to launch

https://alt-romes.github.io/posts/2026-01-30-from-side-project-to-kickstarter-a-walkthrough.html
1•romes•3m ago•0 comments

How to quickly run your own ClawdBot/OpenClaw on AWS

https://deadneurons.substack.com/p/how-to-quickly-run-your-own-clawdbotopenclaw
1•nr378•10m ago•0 comments

Why is everyone pretending Moltbook is for bots?

https://news.ycombinator.com/submitted?id=72ave2
1•72ave2•10m ago•1 comments

I Test Drove a Chinese EV. Now I Don't Want to Buy American Cars Anymore

https://www.wsj.com/tech/personal-tech/chinese-ev-test-drive-xiaomi-su7-c3e59282
3•dkobia•11m ago•0 comments

Japan's Kioxia extends memory chip JV with SanDisk, receiving $1B

https://asia.nikkei.com/business/tech/semiconductors/japan-s-kioxia-extends-memory-chip-jv-with-s...
1•walterbell•11m ago•0 comments

Ask HN: How do you give AI enough Java-specific context before code generation?

1•decebals•12m ago•1 comments

Zero-Knowledge Privacy Infrastructure for Solana

1•2r1in•17m ago•0 comments

Anthropic 'destructively' scanned books to build Claude

https://www.washingtonpost.com/technology/2026/01/27/anthropic-ai-scan-destroy-books/
3•Anon84•17m ago•0 comments

Show HN: Prompt-injection firewall for OpenClaw agents

https://github.com/ContextFort-AI/clawdbot-runtime-controls
1•ashwinr2002•18m ago•0 comments

What makes an engineer when everyone can vibe code

https://twitter.com/rohit4verse/status/2018013775023263806
1•7777777phil•19m ago•0 comments

Trust in Ranking

https://www.marginalia.nu/log/a_130_trust_in_ranking/
1•signa11•19m ago•0 comments

What do people use for Text-to-Voice?

1•bbyford•20m ago•0 comments

When AI Assumes We Know

https://www.psychologytoday.com/us/blog/the-digital-self/202601/when-ai-assumes-we-already-know
1•omkar-foss•20m ago•0 comments

I calculated what 1M tokens costs across 50 LLM models

https://withorbit.io/blog
1•harshit19932703•22m ago•0 comments

Show HN: I built a digital clock with a 3D-printed case, custom PCB, and Arduino

https://boxart.lt/blog/diy_digital_clock
1•roadsidejesus•22m ago•0 comments

Claude for Excel system prompt, tools and beta headers

https://twitter.com/hewliyang/status/2018278447429382531
1•hewliyang•30m ago•0 comments

To Every Developer Close to Burnout, Read This · TheSeniorDev

https://www.theseniordev.com/blog/to-every-developer-close-to-burnout-read-this
1•birdculture•30m ago•0 comments

Show HN: Judgment Boundary – Stop as a First-Class Outcome for AI Systems

https://github.com/Nick-heo-eg/stop-first-rag
1•echoos•32m ago•1 comments

Copy Protection in Jet Set Willy

https://intarch.ac.uk/journal/issue45/2/1.html
1•Dachande663•32m ago•0 comments

DNS Mesh with eBPF

2•woodprogrammer•32m ago•0 comments

Build chatbot to talk with your PostgreSQL database using Python and local LLM

https://mljar.com/blog/chatbot-python-postgresql-local-llm/
1•pplonski86•34m ago•0 comments

New satellite view of Tibet's tectonic clash

https://www.esa.int/Applications/Observing_the_Earth/Copernicus/Sentinel-1/New_satellite_view_of_...
2•layer8•34m ago•0 comments

Android + termux + pi

https://twitter.com/badlogicgames/status/2018200939979526335
2•tosh•37m ago•0 comments

A Pyrrhic Victory?

https://zhaoxo.substack.com/p/a-pyrrhic-victory
1•shrinkzxo•37m ago•0 comments

We Developed a Rule Database

1•rockeetterark•37m ago•0 comments

Show HN: Uruflow – A self-hosted, lightweight CI/CD server written in Go

https://github.com/urustack/uruflow
1•musnas•40m ago•0 comments

Show HN: WonderPic – Turn photos into cartoons/sketches (Free, No Login)

https://www.wonderpic.art/
1•Sharon111•43m ago•1 comments