frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

National Design Service Websites Registry

https://thedreydossier.github.io/NDS_servers_map/
1•ravenical•1m ago•0 comments

Normalized Compression Distance

https://en.wikipedia.org/wiki/Normalized_compression_distance
1•woliveirajr•1m ago•0 comments

Another tech company says it will cut jobs amid pivot to AI

https://www.latimes.com/business/story/2026-05-29/another-tech-company-says-it-will-cut-hundreds-...
1•1vuio0pswjnm7•1m ago•0 comments

Zero Evidence of AI-Related Job Losses

https://www.apollo.com/wealth/the-daily-spark/zero-evidence-of-ai-related-job-losses
1•akyuu•1m ago•0 comments

Generative Unix CTF for RL

https://vmax.ai/team/unix-ctf-procedural-environments-for-unix-competence-reinforcement-learning
1•ronald_raygun•2m ago•0 comments

Open-source security mess: IBM and Red Hat bet $5B and 20k engineers can fix it

https://www.zdnet.com/article/open-source-security-is-a-mess-ibm-and-red-hat-bet-5-billion-to-fix...
1•CrankyBear•3m ago•0 comments

AionOS – self-healing microkernel in Zig (boots on real hardware)

https://github.com/rodancz/aion
1•rodancz•3m ago•0 comments

The origin of quorum systems in distributed computing [pdf]

https://vukolic.com/QuorumsOrigin.pdf
1•fanf2•3m ago•0 comments

Are all BSDs created equally? OpenBSD vs. NetBSD vs. FreeBSD (2018) [video]

https://www.youtube.com/watch?v=AvSPqo3_3vM
2•Caarticles•5m ago•0 comments

To see to it that the forces of Napoleon are driven out of Spain (1809)

https://wellsoc.org/society-member-pages/anecdotes-of-wellington/
2•backuprestore•5m ago•0 comments

Show HN: Train Claude Code's replacement (ds4 and pi and aoe)

https://github.com/njbrake/dotpi/tree/main
1•river_otter•7m ago•0 comments

But It Happened [video]

https://www.youtube.com/watch?v=tlQ7EoJDTQY
1•stock_toaster•8m ago•0 comments

The Religion of Speed

https://graybearding.bearblog.dev/the-religion-of-speed/
1•rglover•8m ago•0 comments

Waymo launches cheaper robotaxis in Los Angeles

https://www.latimes.com/business/story/2026-05-28/waymo-launches-services-with-cheaper-robotaxis-...
1•gamblor956•10m ago•0 comments

Any Cloud. Locally – New floci's brothers

https://floci.io
1•hectorvent•10m ago•0 comments

SiteGround's Icky Approach to AI in WordPress 7.0

https://www.rhyswynne.co.uk/sitegrounds-icky-approach-to-ai-in-wordpress-7-0/
1•speckx•13m ago•0 comments

Tokyo rent map: ¥70k gap between cheapest and priciest 1K (May 2026 data)

https://housingassist.com/blog/tokyo-rent-report-may-2026/
3•momentmaker•15m ago•0 comments

SpaceX skeptics' added reason for concern: Musk comments diverge from IPO filing

https://www.cnbc.com/2026/05/29/spacex-skeptics-concerned-as-musk-comments-diverge-from-ipo-filin...
4•1vuio0pswjnm7•15m ago•0 comments

SpaceX's index fund debut will look nothing like what most investors expect

https://www.investmentnews.com/practice-management/spacexs-index-fund-debut-will-look-nothing-lik...
4•avidiax•16m ago•1 comments

OldPhilly: Mapping historical photos from the Philadelphia City Archive

https://oldphilly.org/
2•h0rv•16m ago•0 comments

Why Your Pentest Report Is Lying to You (and What to Do About It)

https://www.pentesty.co/blog/why-your-pentest-report-is-lying-to-you
2•czaar•16m ago•0 comments

EU-Backed Appeals Center Accidentally Confirms DSA Censorship Regime Is Broken

https://reclaimthenet.org/eu-dsa-appeals-centre-report-exposes-content-censorship-failures
3•anonymousiam•19m ago•0 comments

Show HN: Sverklo – repo memory for coding agents

https://sverklo.com/
3•nike-17•20m ago•0 comments

It's Front end's Lost Decade [video]

https://www.youtube.com/watch?v=7ge8iwaNNAw
4•tosh•22m ago•0 comments

Unpatched Ollama Vulnerabilities: Phishing Overlays and Data Exfiltration

https://www.promptarmor.com/resources/unpatched-ollama-vulnerabilities-phishing-overlays-and-data...
5•Kneenex•25m ago•0 comments

Ask HN: If I cancel Codex today whats the next best local inference agent?

3•Bulbasaur2015•25m ago•1 comments

SpaceX and the 'Enshittification' of Markets

https://www.ft.com/content/f724d500-fd45-4f38-86b8-549b5cae88ba
5•avidiax•26m ago•0 comments

Low-Level Network Optimizations: Socket Options That Matter

https://goperf.dev/02-networking/low-level-optimizations/
2•thunderbong•26m ago•0 comments

Why Teachers Quit [video]

https://www.youtube.com/watch?v=CPcxpcCgZMw
2•obscurette•27m ago•0 comments

Megastorm: Multi-framework brainstorming for Claude Code/Cowork

https://creativepm.substack.com/p/megastorm
2•Roll_The_Bones•28m ago•0 comments