frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: ElementaryUI – A Swift front end framework for the browser

https://elementary.codes
1•simonleeb•48s ago•0 comments

Computer Science Illustrated (2009) [pdf]

https://www2.eecs.berkeley.edu/Pubs/TechRpts/2009/EECS-2009-79.pdf
1•swatson741•3m ago•0 comments

Grok's deepfake images investigated by Australia's online safety watchdog

https://www.theguardian.com/technology/2026/jan/07/grok-deepfake-images-sexualise-women-children-...
1•josefresco•5m ago•0 comments

Pgpm: A Package Manager for Modular PostgreSQL

https://www.postgresql.org/about/news/introducing-pgpm-a-package-manager-for-modular-postgresql-3...
1•emschwartz•5m ago•0 comments

Grok Is Pushing AI 'Undressing' Mainstream

https://www.wired.com/story/grok-is-pushing-ai-undressing-mainstream/
1•josefresco•6m ago•0 comments

New Veeam vulnerabilities expose backup servers to RCE attacks

https://www.bleepingcomputer.com/news/security/new-veeam-vulnerabilities-expose-backup-servers-to...
1•fleahunter•11m ago•0 comments

Ask HN: What Is a Freedom for You?

2•eimrine•12m ago•0 comments

Show HN: Put Greenland on the Moon (interactive map for size compare)

https://github.com/ObservedObserver/world-map-reality
2•loa_observer•12m ago•0 comments

Tessellation Art

https://tiled.art/en/home/?id=dinosaurs12
2•bookofjoe•13m ago•0 comments

AWS and Microsoft are selling more than cloud services

https://berthub.eu/articles/posts/aws-and-microsoft-are-selling-much-more-than-cloud/
3•tomwas54•15m ago•0 comments

Diversity Vs Density: A data strategy comparison for fine-tuning VLMs

https://huggingface.co/blog/Akhil-Theerthala/diversity-density-for-vision-language-models
2•silvervein•15m ago•1 comments

Lego Smart Brick

https://www.theverge.com/tech/855520/i-played-with-the-lego-smart-brick
2•ddmng•16m ago•0 comments

A Company Came Up with a Different Approach: Fuel Without Petroleum

https://dailygalaxy.com/2026/01/fuel-from-air-machine-no-oil-clean-fuel-tesla-ev-alternative/
3•thelastgallon•17m ago•0 comments

xAI raises $20 billion to expand Grok AI models and enterprise tools

https://www.testingcatalog.com/xai-raises-20-billion-to-expand-grok-ai-models-and-enterprise-tools/
2•redm•17m ago•0 comments

Ask HN: Thoughts on a causality-first programming language in Rust?

4•k_aakash•18m ago•0 comments

File over App Is a Philosophy

https://twitter.com/kepano/status/1675626836821409792
4•bilsbie•18m ago•0 comments

Market Beliefs about Open vs. Closed AI

https://arxiv.org/abs/2512.14969
2•50kIters•20m ago•0 comments

Can you review my online toolbox website?

https://omnvert.com/en
3•kaant•21m ago•1 comments

Imec Makes Solid-State Nanopores Using EUV Lithography

https://www.eetimes.com/imec-makes-solid-state-nanopores-using-euv-lithography/
1•giuliomagnifico•24m ago•0 comments

A4 Paper Stories

https://susam.net/a4-paper-stories.html
4•blenderob•24m ago•0 comments

Alpie Core: a 32B reasoning model trained and served at 4-bit

https://huggingface.co/169Pi/Alpie-Core
1•ChiragArya•24m ago•2 comments

Why I Built My AI Agent in Rust as a non-developer (and what I'd do differently)

https://refreshagent.com/engineering/building-ai-agents-in-rust
1•35mm•24m ago•1 comments

Apple Reportedly Exploring Multispectral Imaging for Future iPhones

https://www.macrumors.com/2026/01/07/apple-multispectral-imaging-future-iphones/
1•mgh2•24m ago•0 comments

I built a simple tool to protect your real email from spam

https://emailshield.app
1•redditmarketing•25m ago•1 comments

Progress made on AI-powered humanoid robots [video]

https://www.youtube.com/watch?v=CbHeh7qwils
2•mgh2•26m ago•0 comments

A Waterfall Tour of the Chattahoochie National Forest in North Georgia

https://whitneylee.com/2026/01/07/during-the-holiday-break-i.html
1•mooreds•26m ago•0 comments

Visibility Is Velocity

https://michaelheap.com/visibility-is-velocity/
1•mooreds•27m ago•0 comments

Implementing OPA: Comprehensive Overview and Practical Examples (2024)

https://permify.co/post/implementing-opa/
1•mooreds•28m ago•0 comments

What's Interesting about TigerBeetle?

https://softwaremill.com/whats-interesting-about-tigerbeetle/
1•jorangreef•29m ago•0 comments

Everything Nvidia announced at CES 2026

https://coinheadlines.com/news/heres-everything-nvidia-announced-at-ces-2026/article-24867/
1•Johann-Wilfred•30m ago•0 comments