frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Fable 5 is available in Zed

https://github.com/zed-industries/zed/pull/58957
1•flaburgan•1m ago•1 comments

Claude Fable 5 Ultracode + AI medical diagnosis

https://github.com/joelparkerhenderson/ai-medical-diagnosis-examples/blob/main/doctor-perspective...
1•jph•2m ago•0 comments

Moon Mnf: magic wands,idiots, first principal

https://www.lmcpress.com/
1•AITripleAce•3m ago•0 comments

Rejected Emoji Proposals

https://charlottebuff.com/unicode/misc/rejected-emoji-proposals/
1•cheeaun•8m ago•0 comments

Firefox for Android: Play Integrity Check Challenges Custom ROM Users

https://serverhost.com/blog/firefox-for-android-play-integrity-check-challenges-custom-rom-users/
1•shaunpud•10m ago•0 comments

Australian SaaS Platforms Can Verify Business Users with ABN Data

https://fastbusinessapi.com/article/how-australian-saas-platforms-can-verify-business-users-with-...
2•ApiFB-Dev•11m ago•0 comments

Principles for Agent-Native CLIs

https://trevinsays.com/p/10-principles-for-agent-native-clis
1•saikatsg•13m ago•0 comments

From the Transistor to the Web Browser

https://github.com/geohot/fromthetransistor
1•pythops•15m ago•0 comments

David Sinclair plans to test whole-body rejuvenation drugs in the xPrize compet

https://www.technologyreview.com/2026/06/09/1138545/david-sinclair-plans-to-test-whole-body-rejuv...
1•joozio•19m ago•0 comments

Compute-to-Surplus: Why AI Progress Doesn't Matter Until It Changes Economics

https://signal-memo.com/memo-the-compute-to-surplus-pipeline-is-a-product-spec-heres-how-to-ship-...
1•alex-ivan•20m ago•0 comments

Show HN: What Sound Looks Like [video]

https://www.youtube.com/watch?v=XvkDwInPYJw
1•FionaZhu•21m ago•0 comments

Lawyers Barred for A.I.-Generated Citations to Fake Cases

https://www.nytimes.com/2026/06/09/us/ai-lawyers-sanctioned-mississippi.html
2•iancmceachern•24m ago•0 comments

Don't Be Stupid: Grasp Solid

https://www.npopov.com/2011/12/27/Dont-be-STUPID-GRASP-SOLID.html
1•prakashqwerty•24m ago•0 comments

Show HN: Leash, a low-dopamine mobile browser replacement

https://leash.ax
2•hemmert•24m ago•4 comments

CIA officer arrested with gold bars accused of making up top secret program

https://www.nbcnews.com/politics/national-security/cia-officer-arrested-gold-bars-accused-making-...
3•u1hcw9nx•31m ago•0 comments

Self-Prompt

https://selfprompt.dev/posts/2026-06-08-self-prompt
1•pro_methe5•31m ago•0 comments

The Revenge of the Publicists: How Comms Execs Stormed the C-Suite

https://www.wsj.com/cmo-today/the-revenge-of-the-publicists-how-comms-execs-stormed-the-c-suite-2...
1•doener•33m ago•0 comments

USB Devices – OrbStack Docs

https://docs.orbstack.dev/features/usb
2•watermelon0•33m ago•0 comments

CrossOver 26.2.0

https://www.codeweavers.com/support/forums/announce
2•doener•44m ago•0 comments

What I Got Right and Wrong Building a Solo Project Around Real Life

https://medium.com/@ivan_49508/what-i-got-right-and-wrong-building-a-solo-project-around-real-lif...
3•enjoyminded•48m ago•0 comments

Ask HN: What is the best way to learn game logic programming for beginners?

1•huzaifasinan•49m ago•0 comments

Computer Lessons - A history of computers in education

https://technicshistory.com/2026/06/06/computer-lessons/
2•the-mitr•50m ago•0 comments

Show HN: RAG built for Frappe using TurboVec

https://github.com/ssenthilnathan3/turbo_rag
1•nathaah3•51m ago•0 comments

Claude Fable 5's new features, tested by having it write its own launch coverage

https://medium.com/@alirezarezvani/claude-fable-5-guide-for-claude-code-11501ceb78a8
1•jungard•53m ago•0 comments

Anthropic is intentionally nerfing Fable when asked to develop other LLMs

https://old.reddit.com/r/LocalLLaMA/comments/1u1s2oz/anthropic_is_intentionally_nerfing_fable_when/
2•theanonymousone•54m ago•0 comments

EU to favor European satellite services to prevent Musk's Starlink expansion

https://www.euronews.com/my-europe/2026/05/26/eu-to-favour-european-satellite-services-to-prevent...
4•hbarka•57m ago•1 comments

VibeOS [video]

https://www.youtube.com/watch?v=zh6fMtL_cSM
1•nreece•57m ago•0 comments

Sonny Piers elaborates on his ban from the Gnome community

https://discourse.gnome.org/t/2026-board-candidate-robert-mcqueen/35308
3•RandomGerm4n•1h ago•0 comments

Vibe Rounds in Healthcare

https://archive.org/details/vibe-rounds-concept-document
1•dravinash•1h ago•1 comments

TokenLens

1•navrekh•1h ago•0 comments