frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

ICE has spent over $25M on iris scanners in no-bid contracts

https://www.npr.org/2026/05/27/nx-s1-5822429/ice-buys-iris-scanners-tech-tools
1•ck2•12s ago•0 comments

The GitHub Actions Tax

https://cloudposse.com/newsletter/production-ready/2026-05-github-actions-tax
1•mooreds•39s ago•0 comments

The future of AI-native work

https://anandchowdhary.com/blog/2026/future-ai-native-work
1•anandchowdhary•39s ago•0 comments

Envato did my marketing for 12 years. Now I'm lost. Where do I start?

https://www.indiehackers.com/post/envato-did-my-marketing-for-12-years-now-i-m-lost-where-do-i-st...
1•veno_es•56s ago•0 comments

California defeats Tesla's attempt to throw out racial discrimination lawsuit

https://arstechnica.com/tech-policy/2026/05/california-defeats-teslas-attempt-to-throw-out-racial...
2•Brajeshwar•1m ago•0 comments

Dancing Mad with Sandboxing

https://xeiaso.net/blog/2026/dancing-mad-sandboxing/
1•xena•1m ago•0 comments

K Slices, K Dices

https://beyondloom.com/blog/slicedice.html
1•tosh•3m ago•0 comments

How We Test AI: LLM and GenAI Security Methodology at Anvil Secure

https://www.anvilsecure.com/blog/llm-genai-security-methodology-at-anvil-secure.html
1•anvilsecure•4m ago•0 comments

Testing = slow? Yeah, that's by design, you dipshit

https://www.maaikebrinkhof.nl/testing-slow-yeah-thats-by-design-you-dipshit/
2•linhns•7m ago•0 comments

Building a peer-to-peer alternative to Cloudflare Tunnels with edge TLS certs

https://pangolin.net/news/building-a-peer-to-edge-peer-reverse-proxy
5•miloschwartz•7m ago•0 comments

Show HN: Agentic Intent Benchmark

https://github.com/intent-bench/intent-bench
1•ryan4rtmx•8m ago•0 comments

Show HN: AgentSite – Same bytes to every visitor; Markdown twin at <body> top

https://agentsite.app/
2•dguiley•8m ago•0 comments

Scientists break 30-year superconductivity record at normal pressure

https://www.sciencedaily.com/releases/2026/05/260527023220.htm
2•foota•8m ago•0 comments

Who Wants to Work Anyway?

https://dschreiber.substack.com/p/who-wants-to-work-anyway
2•dimfisch•11m ago•1 comments

Oura Ring 5

https://www.bloomberg.com/news/articles/2026-05-28/oura-ring-5-40-smaller-more-like-regular-ring-...
3•ramonga•12m ago•1 comments

Why do LLM keys all start with sk?

2•swaraj•13m ago•1 comments

Oura Ring 5

https://ouraring.com/blog/inside-the-ring-oura-ring-5/
3•tosh•13m ago•0 comments

NYED Data Explorer Shows 15 Years of Charter School Success

https://redwallanalytics.com/posts/2023-02-22-nyed-data-explorer-shows-15-years-of-charter-school...
1•sebg•14m ago•0 comments

How do you process your "saved but never watched" content pile?

https://github.com/TheBVL/DRIP
1•thebvl•16m ago•1 comments

Why the US job market is so hard, especially for recent college graduates

https://www.msn.com/en-us/news/us/why-the-us-job-market-is-so-hard-especially-for-recent-college-...
2•thehoff•17m ago•2 comments

Problem with Contract Analysis AI

1•rohisinh•18m ago•0 comments

A multi-tool agent harness: graph routing, middleware, and state budgets

https://github.com/Bella3202019/promptloop/blob/main/docs/The_Harness_Behind_Deep_Agent.md
1•velapod•19m ago•0 comments

Valve Takes Crazy Pills and Jacks Up Steam Deck Pricing

https://boilingsteam.com/valve-takes-crazy-pills-and-jacks-up-steam-deck-pricing/
2•ekianjo•20m ago•0 comments

Intel Hyperscan: How We Match Regular Expressions

https://www.intel.com/content/www/us/en/collections/libraries/hyperscan/regular-expression-match....
1•tosh•21m ago•0 comments

Ask HN: Wishlist for an Immich-macOS-App?

2•markusMB•22m ago•0 comments

The Mississippi Miracle

https://en.wikipedia.org/wiki/Mississippi_Miracle
1•panny•22m ago•0 comments

I Tried to Sell My House with a Chatbot

https://www.nytimes.com/2026/05/28/technology/sell-house-with-ai-no-realtor.html
1•burkaman•23m ago•1 comments

Only 17% of all 64-bit Integers are products of two 32-bit integers

https://lemire.me/blog/2026/05/22/only-17-of-all-64-bit-integers-are-products-of-two-32-bit-integ...
2•sebg•26m ago•0 comments

Show HN: Free open source coding models in Slack

https://www.runcord.com/
2•ramonga•26m ago•0 comments

EaglePress – v2.0 milestone, Blog with Python3 and PostgreSQL

https://eaglepress.org/
1•eagle10ne•27m ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.