frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

ChatGPT Is Down

https://chatgpt.com
1•axsaucedo•42s ago•0 comments

Show HN: Save and store you .env vars

https://envmanager.com/
1•pwbgerrits•58s ago•0 comments

Capital Factory CEO Joshua Baer killed in plane crash near Laredo, TX

https://cbsaustin.com/news/local/capital-factory-ceo-joshua-baer-killed-in-plane-crash-near-lared...
2•teach•2m ago•0 comments

World Cup 2026 CLI Dashboard

https://github.com/mansueli/world-cup-2026-cli-dashboard
1•mansueli•2m ago•0 comments

HelpNearby reached 25 countries in 20 days – built by 15-year-old for Sudan

https://help-nearby.org
1•Hyrezyxx•3m ago•0 comments

The Competitive Moat That AI Can't Replicate

https://ghostinthedata.info/posts/2026/2026-06-13-human-connection-moat/
1•speckx•4m ago•0 comments

Poland Invests $11M in ElevenLabs to Build AI Tech Hub

https://www.bloomberg.com/news/articles/2026-06-17/poland-invests-11-million-in-elevenlabs-to-bui...
1•01-_-•4m ago•0 comments

Ford's New $30k Electric Truck

https://carbuzz.com/ford-universal-vehicle-platform-30000-dollar-truck/
1•rationalist•4m ago•1 comments

A $40M Gold Heist Risks Exposing CIA's Top-Secret Spy Programs

https://www.wsj.com/politics/national-security/a-40-million-gold-heist-risks-exposing-cias-top-se...
1•bookofjoe•4m ago•1 comments

Submit your Boarding pass for the Roman Telescope

https://my.nasa.gov/specialevents/s/send-your-name-with-nancy-roman
1•MutexMaven•8m ago•1 comments

Inner monologues are still a mystery

https://www.npr.org/2026/06/08/nx-s1-5847933/inner-monologue-voices-language-brain
3•gmays•9m ago•0 comments

When People Cut Back on Instagram, Where Do They Go?

https://www.mondayeconomist.com/p/quitting-social-media
1•NomNew•10m ago•0 comments

FMAG: A single-instruction GPU virtual machine and toolchain

https://github.com/jangafx/FMAG
1•adamrezich•10m ago•0 comments

Only 16 Percent of Americans Think AI Will Have a Positive Impact on Society

https://techcrunch.com/2026/06/17/only-16-percent-of-americans-think-ai-will-have-a-positive-impa...
3•karakoram•10m ago•0 comments

SpaceX acquires Cursor for $60B. Can it fix Musk's coding division?

https://thenewstack.io/spacex-cursor-ai-coding/
1•Brajeshwar•11m ago•0 comments

Show HN: A free dataset, Polymarket's 5-minute crypto markets, second-by-second

https://kacho.io/polymarket-5min-crypto-dataset
1•kachoio•12m ago•0 comments

Pentagon says Grok has been used to launch missiles at Iran

https://thehill.com/policy/technology/5928204-pentagon-musk-grok-chatbot-iran-strikes/
2•theanonymousone•12m ago•0 comments

Year of free HPE software a "step in the correct direction" in VMware rivalry

https://arstechnica.com/information-technology/2026/06/hpe-tempts-vmware-users-partners-with-year...
1•joozio•14m ago•0 comments

Agentic Resource Discovery Specification

https://agenticresourcediscovery.org/introduction/
1•damick•15m ago•0 comments

What's behind the mania for World Cup stickers in Argentina?

https://www.rte.ie/brainstorm/2026/0617/1578752-world-cup-stickers-argentina-collectors-public-ga...
1•austinallegro•15m ago•0 comments

European Commission embraces private closed-source W Social platform

https://ec.social-network.europa.eu/@EUCommission/116766280029168108
1•rapnie•16m ago•0 comments

Show HN: Mantyx – Batteries included managed agent runtime

https://mantyx.io/
1•mantyx•17m ago•0 comments

Initial Commit

https://www.khanna.law/blog/initial-commit
1•hkhanna•17m ago•2 comments

Robinhood CEO Says 'Business Has Never Been Stronger' Then Cuts 10% of Workforce

https://www.ibtimes.co.uk/robinhood-workforce-reduction-strong-performance-1803179
4•randycupertino•19m ago•2 comments

Ask HN: Successful entrepreneurs and indie hackers, enlighten me

2•markosn•20m ago•0 comments

Show HN: BookLike – Chrome reader mode with eBook-style page flips

https://booklike.app/
1•fachkamera•21m ago•1 comments

CVE-2026-42530: Nginx 1.30.2 and Nginx 1.31.2

https://www.cve.org/CVERecord?id=CVE-2026-42530
2•petecooper•21m ago•0 comments

Self-hosted Directus 12 requires a license key to lift caps

https://github.com/directus/directus/releases/tag/v12.0.0
1•jclaveau•22m ago•0 comments

Print Design Tips for Engineers

https://papermill.io/blog/print-design-tips-for-engineers
2•davidpapermill•22m ago•2 comments

Agents are under-elicited: A case study in optimization tasks

https://fulcrum.inc/2026/06/12/agents-are-under-elicited.html
1•etherio•22m ago•0 comments