frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Memoir – Git for AI agent memory, with a Claude Code plugin

https://github.com/zhangfengcdt/memoir
1•memoir_ai•21s ago•0 comments

Industrial Society and Its Future [pdf]

https://web.cs.ucdavis.edu/~rogaway/classes/188/materials/Industrial%20Society%20and%20Its%20Futu...
1•0x4e•39s ago•0 comments

Vertically Aligning Roman Numerals in Code

https://shkspr.mobi/blog/2026/05/vertically-aligning-roman-numerals-in-code/
1•blenderob•54s ago•0 comments

Shortages push long-term supply agreements for SSDs and HDDs to record 5 years

https://www.tomshardware.com/pc-components/ssds/crushing-shortages-have-pushed-long-term-supply-a...
1•layer8•3m ago•0 comments

App I made to make waking up more fun (not an Agentic AI B2B SaaS startup)

https://apps.apple.com/us/app/unsnooze-challenge-alarm-clock/id6758871228
1•cnnadozi•3m ago•0 comments

You Don't Love Systemd Timers Enough

https://blog.tjll.net/you-dont-love-systemd-timers-enough/
2•Tomte•4m ago•0 comments

Persistent Iterators with Value Semantics

https://arxiv.org/abs/2604.14072
1•matt_d•4m ago•0 comments

Finding the differences in a series of power supplies

https://www.lttlabs.com/articles/2026/05/05/testing-psu-series
1•LabsLucas•5m ago•0 comments

Instagram Encrypted Messaging Ends on Friday, May 8

https://www.macrumors.com/2026/05/05/psa-instagram-encrypted-messaging-ends-may-8/
1•fraXis•5m ago•0 comments

EEVblog: The 555 Timer is 55 years old

https://www.youtube.com/watch?v=6JhK8iCQuqI
2•brudgers•7m ago•0 comments

Show HN: The SkillForge – skills-first credentials for software engineers

https://theskillforge.com
1•roymain•8m ago•0 comments

Show HN: I built an API for agents visiting my personal website

https://mczaykowski.com/articles/smallest-ax-surface
2•selvmvde•9m ago•0 comments

SubQ – a major breakthrough in LLM intelligence

https://twitter.com/alex_whedon/status/2051663268704636937
3•vanni•10m ago•0 comments

WolfPSA: PSA Crypto Compatibility Powered by WolfCrypt

https://github.com/wolfSSL/wolfPSA
1•aidangarske•10m ago•0 comments

Testers – 12 Testers Community

https://play.google.com/store/apps/details?id=com.thardstudio.testers&hl=en_US
1•mdaside•11m ago•1 comments

Ask HN: What tech hobbies are worth exploring?

4•merek•12m ago•1 comments

ArkTunnel, censorship-resistant tunnel that hides behind a real Bitcoin node

https://github.com/st-hannibal/ArkTunnel
1•st-hannibal•12m ago•0 comments

Peter Thiel on the Future of Legal Technology – Notes Essay (2012)

https://www.tumblr.com/blakemasters/37411481044/peter-thiel-on-the-future-of-legal-technology
1•ronfriedhaber•12m ago•0 comments

2026 Puzzle Design Competition: Entries

https://puzzleworld.org/DesignCompetition/2026/
1•robinhouston•13m ago•0 comments

Google, xAI and Microsoft agree to US national security reviews of new AI models

https://www.ft.com/content/c4435dd4-00c0-4270-aab9-3c7ce1ae45f6
1•merksittich•14m ago•0 comments

Show HN: Why Two Identical PDFs Have Different SHA-256 Hashes (How We Fixed It)

https://docs.pdfcanon.com/blog/why-identical-pdfs-hash-differently/
1•napzoom•16m ago•2 comments

Agent Orchestration Models

2•archer423•17m ago•0 comments

Wordy – Solving SEO Overkill with Information Theory and Stochastic Inference

https://wordy.runtime-hub.com/
1•RunTimeZero•18m ago•0 comments

Build you a personal assistant agent for fun and profit

https://techstackups.com/guides/build-personal-assistant-agent/
3•sixhobbits•20m ago•0 comments

Show HN: iOS SimulatorCamera – use your MacBook camera with iOS simulators

https://github.com/Akylas/SimulatorCamera
1•farfromrefuge•21m ago•0 comments

Achieving CVE Remediation in an Era of Escalating Vulnerabilities

https://flox.dev/blog/achieving-rapid-cve-remediation-in-an-era-of-escalating-vulnerabilities/
1•ronef•21m ago•1 comments

Show HN: Open-Source DesignMD Generator

https://www.designmd.supply/
2•ICodeSometimes•22m ago•0 comments

Offline Local AI for Protest

https://apps.apple.com/us/app/outcry-activist-ai-mentor/id6762086768
1•micahwhite•22m ago•0 comments

PageIndex: Vectorless, Reasoning-Based RAG

https://github.com/VectifyAI/PageIndex
1•garyclarke27•22m ago•0 comments

Don't Outsource Your Understanding

https://leehanchung.github.io/blogs/2026/05/01/dont-outsource-your-understanding/
1•freediver•23m ago•0 comments