frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

The Return of the Energy Transition

https://steelforfuel.substack.com/p/the-return-of-the-energy-transition
1•simonebrunozzi•59s ago•0 comments

Leaked Alleged Text of Trump-Iran Deal

https://www.mediaite.com/media/news/read-leaked-alleged-text-of-trump-iran-deal/
1•cf100clunk•1m ago•1 comments

Hillock – Local, brain-inspired AI memory using SQLite and HDC

https://github.com/roandejager/Hillock
1•roandejager•1m ago•0 comments

Build Your Own Eval Harness from Scratch with Bun and Claude -p

https://alexop.dev/posts/build-your-own-eval-harness-bun-claude-p/
1•speckx•2m ago•0 comments

Claude recursive subagents burning hundreds in extra tokens

https://bsky.app/profile/ed3d.net/post/3moggsr47dk2z
2•belkinpower•2m ago•0 comments

Webview – cross-platform HTML5 UI abstraction layer

https://github.com/webview/webview
1•smartmic•2m ago•0 comments

Show HN: VoiceDraw – Talk system design out loud, the diagrams draw themselves

https://voicedraw.com/
3•ajaypanthagani•4m ago•0 comments

Implementing transformative role playing games

https://books.uu.se/uup/catalog/book/55
2•bythreads•4m ago•0 comments

Cascading Tree Sitter Queries

https://github.com/jasper-lyons/ctsq
2•iovrthoughtthis•5m ago•1 comments

Ericsson CEO Ekholm to step down, be replaced by Per Narvinger

https://www.reuters.com/business/ericsson-ceo-step-down-be-replaced-by-per-narvinger-2026-06-16/
2•michalhuman•7m ago•0 comments

Is your company affected by NIS2?

https://nisd2.eu/applicability
2•cjhisey•7m ago•0 comments

Canada Is Building a Surveillance State

https://twitter.com/lucyhargreaves4/status/2066903272271544551
5•arrowsmith•8m ago•0 comments

OpalAI Got Two NASA Contracts to Build AI for Wildfire Intelligence

https://www.opal-ai.com
3•opalai•9m ago•0 comments

VTCLab Media Analyzer v0.6.0 is out

https://media-analyzer.pro/blog/posts/2026-06-16-v0.6.0/
2•ksh2u•9m ago•0 comments

MambAdapter: Lightweight Mamba-Based Adapters for Transfer Learning

https://arxiv.org/abs/2606.15638
2•MediaSquirrel•9m ago•0 comments

Pyinfra – agentless infrastructure automation, in plain Python

https://pyinfra.com
3•birdculture•10m ago•0 comments

Music Labels Win Canadian Site Blocking Order Against YouTube Downloaders

https://torrentfreak.com/music-labels-win-canadian-site-blocking-order-against-y2mate-ytmp3-and-s...
2•Cider9986•10m ago•0 comments

Apparently the Real Reason Anthropic's Models Are Offline: A Six-Year-Old Grudge

https://www.techdirt.com/2026/06/16/apparently-the-real-reason-anthropics-models-are-offline-a-si...
4•cdrnsf•12m ago•0 comments

To Get More Replies, Say Less (2017)

https://www.gkogan.co/increase-reply-rates/
3•downbad_•15m ago•0 comments

Leviathan Waking – On Anthropic/USG, and a new era in AI governance

https://www.hyperdimensional.co/p/leviathan-waking
2•speckx•16m ago•0 comments

Show HN: Dev-friendly native OTel: only OSS stateful, on-the-wire Observability

3•jratkevic•17m ago•0 comments

The Web We Know Is Going to Disappear

https://www.minid.net/2026/6/15/the-web-is-going-to-dissapear
4•taubek•20m ago•0 comments

A technical guide to building your own learning loop

https://twitter.com/GokuMohandas/status/2066853420326384055
3•gokumd•20m ago•0 comments

Inference cost at scale with napkin math

https://injuly.in/blog/napkin-inference-cost/index.html
2•gmays•20m ago•0 comments

Why do we do astrophysics?

https://arxiv.org/abs/2602.10181
2•pcfwik•21m ago•0 comments

Nearly a million passports and photo IDs were unprotected on the public internet

https://www.theverge.com/tech/947157/passports-data-breach-cannabis-club-systems-nefos-puffpal
8•N_A_T_E•23m ago•1 comments

Show HN: Rapunzel – a tree-style tab terminal emulator for Codex Claude Gemini

https://github.com/javaid-codes/rapunzel/tree/main
2•WasimBhai•23m ago•0 comments

My one weird trick for managing my internet addiction

https://scottrogowski.com/my-one-weird-trick-for-managing-my-internet-addiction
2•scottrogowski•24m ago•0 comments

Brendan Sorsby, Texas Tech part ways after gambling scandal, legal fallout

https://www.on3.com/news/brendan-sorsby-texas-tech-mutually-part-ways-after-gambling-scandal-lega...
2•randycupertino•25m ago•0 comments

" Claude Fable 5 was delisted. The answer isn't a bigger model – it's a panel: "

https://www.orcarouter.ai/blog/model-fusion-in-production-inside-orcarouter-fusion-and-the-routin...
2•sangwen•27m ago•0 comments