frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Agent-Native Software Engineering

https://sys0.substack.com/p/agent-native-software-engineering
1•shenli3514•1m ago•0 comments

I built a platform that tracks which software people cancel and regret"

https://www.gotypical.com
1•Gotyypical•1m ago•0 comments

Databento Binary Encoding (DBN)

https://databento.com/docs/standards-and-conventions/databento-binary-encoding
1•ronfriedhaber•1m ago•0 comments

'Ted Lasso' Was Finished. Then Jason Sudeikis Had an Epiphany

https://www.hollywoodreporter.com/tv/tv-features/ted-lasso-returns-jason-sudeikis-interview-seaso...
1•mooreds•2m ago•0 comments

Soaring Egg Prices Are Hitting China Hard

https://www.nytimes.com/2026/07/20/business/china-eggs-expensive.html
2•mooreds•3m ago•0 comments

Lung cancer in nonsmokers: A women's health crisis

https://www.cbsnews.com/news/lung-cancer-non-smoking-women/
1•brandonb•3m ago•0 comments

Dog Photographer Loses Copyright Case over AI-Generated Comic Version of Photo

https://petapixel.com/2026/07/22/dog-photographer-loses-copyright-case-over-ai-generated-comic-ve...
2•dmitrygr•4m ago•0 comments

Cyrus brings coding agents on your own infra to Linear and Slack

https://www.atcyrus.com
1•wateralien•4m ago•1 comments

Pullrun, a runtime that runs same OCI images as containers or VMs

https://github.com/pullrun/pullrun
1•liquid64•5m ago•0 comments

Banks pay backhanded compliments to private credit

https://www.semafor.com/article/07/21/2026/banks-pay-backhanded-compliments-to-private-credit
1•petethomas•5m ago•0 comments

The Subprime Data Center Crisis

https://www.wheresyoured.at/the-subprime-data-center-crisis/
2•crescit_eundo•5m ago•0 comments

I used ChatGPT to sue a Norwegian airline from New York and get $4760

https://www.behind-the-enemy-lines.com/2026/07/the-lawyer-i-never-hired-how-chatgpt.html
1•Panos•5m ago•1 comments

Polio should have been eradicated by now. What's plan B?

https://www.nature.com/articles/d41586-026-02229-6
1•Brajeshwar•5m ago•0 comments

Project: Tether

https://devz.cl/posts/axiom-proper-project-tether/
1•DanielVZ•6m ago•0 comments

DuckDB Internals: Why Is DuckDB Fast? (Part 2 Vectorized Execution)

https://www.greybeam.ai/blog/duckdb-internals-part-2
1•hornyforsavings•7m ago•0 comments

Sneaky Windows stealer targets 300 apps, gives crims AI profiler to max profits

https://www.theregister.com/security/2026/07/22/sneaky-windows-stealer-targets-300-apps-gives-cri...
1•Bender•7m ago•0 comments

Software Apprenticeship Was Accidental

https://caffeinatedcode.com/posts/software-apprenticeship-was-accidental/
1•abnercoimbre•7m ago•0 comments

CLI for Proton Drive now available

https://github.com/ProtonDriveApps/sdk/blob/main/cli/README.md
1•schnittbrot•8m ago•1 comments

Layoffs.FYI Adds new AI attribution layoff chart

https://layoffs.fyi/
1•rickcarlino•8m ago•0 comments

Is BPC-157 legal in 2026? What the FDA found

https://www.empirical.health/blog/bpc-157-fda-review/
1•brandonb•8m ago•0 comments

MCP tool calling under the hood

https://jeffauriemma.leaflet.pub/3mraol7ln622u
1•jdauriemma•8m ago•0 comments

Unlimited AI tokens aren't unlimited after all as US Army burns through supply

https://arstechnica.com/ai/2026/07/us-army-faces-ai-use-limits-after-exhausting-years-supply-of-a...
2•Bender•8m ago•1 comments

What happens when you try to chop a photon in half?

https://arstechnica.com/science/2026/07/what-happens-when-you-try-to-chop-a-photon-in-half/
3•Bender•9m ago•0 comments

Scientists Gave Mice Cocaine. This Is What It Did to Their Brains

https://www.404media.co/mice-cocaine-research-addiction-fens-forum/
1•gmays•9m ago•0 comments

Topcoat: A framework for building full-stack reactive web apps with Rust

https://tokio.rs/blog/2026-07-22-announcing-topcoat
1•carllerche•9m ago•1 comments

We probed a pinned GPT-5.5 endpoint: every request carried ~1,447 hidden tokens

https://tosea.ai/blog/prompt-injection-llm-fingerprint-drift
1•opwizardx•9m ago•0 comments

Manticore Search under systemd: beyond fork, PID files, and guesswork

https://manticoresearch.com/blog/systemd_integration/
1•snikolaev•11m ago•0 comments

A Fast Path for Fixed-Length Lists in Parquet

https://www.morling.dev/blog/fast-path-for-fixed-length-lists-in-parquet/
1•gunnarmorling•11m ago•0 comments

Proofs

https://home.omg.lol/info/proofs
2•Tomte•13m ago•0 comments

Wordit – Now in Pt-Br

https://wordit.org/pt-br/
1•atum47•15m ago•1 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.