frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•7mo ago

Comments

kemotep•7mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Using LLMs at Oxide

https://rfd.shared.oxide.computer/rfd/0576
1•steveklabnik•35s ago•0 comments

Times God Picked a Date

https://www.kcm.org/real-help/faith/learn/10-times-god-picked-date
1•marysminefnuf•3m ago•0 comments

UC Davis scientists created wheat that can partially fertilize itself

https://scitechdaily.com/new-self-fertilizing-wheat-could-transform-farming/
1•methuselah_in•3m ago•0 comments

How UI degrades over time

https://grumpy.website/1723
4•soheilpro•4m ago•0 comments

Puzzling Out the Perytons (2015)

https://www.centauri-dreams.org/2015/04/06/puzzling-out-the-perytons/
1•adagradschool•4m ago•0 comments

Jellyfin does hardware transcoding for free, and Plex wants $250 to match it

https://www.xda-developers.com/jellyfin-hardware-transcoding-free-plex-wants-money/
4•josephcsible•7m ago•0 comments

LokiVector: An Embedded Document Vector DB Crash-Tested Durability

1•rckflr•7m ago•0 comments

Why AI isn't tool calling humans?

https://www.human-tool-call.com/
3•louis030195•8m ago•0 comments

My Next.js server was compromised 24 hours after CVE-2025-55182 disclosure

https://asleepace.com/blog/malware-cve-2025-55182-exploitation-incident-report/
1•asleepace•9m ago•1 comments

7 Deaths and hundreds of injuries are linked to faulty Abbott glucose monitors

https://www.npr.org/2025/12/06/g-s1-101082/abbott-glucose-monitor-deaths-recall-freestyle-libre
6•bookofjoe•11m ago•0 comments

The end of the middle-class traveler in Hawaii is near

https://www.sfgate.com/hawaii/article/hawaii-middle-class-visitors-declining-21204477.php
4•rblion•12m ago•0 comments

A Full Bitcoin-Style Blockchain Implemented in Pure PHP and Sockets

https://github.com/kladskull/xEroS
1•captaincrunch•16m ago•0 comments

OpenAI's Confession Experiment: Teaching AI to Admit When It Cheats

https://kaysnotes.medium.com/openais-confession-experiment-teaching-ai-to-admit-when-it-cheats-40...
3•stopbulying•24m ago•0 comments

European VCs have raised nearly 60% less funding so far in 2025

https://sifted.eu/articles/european-vc-fundraising-2025-down
4•doener•25m ago•0 comments

Deep Dive: The Fed Just Injected $13.5B into Banks – Here's My Take

https://drive.google.com/file/d/1udXwE3tw0tk-CxAePSVRjAFioCVCJYCh/view?usp=sharing
5•AtomInstitute•27m ago•1 comments

We Are Repaganizing

https://firstthings.com/we-are-repaganizing/
3•barry-cotter•28m ago•1 comments

When Free Is Too Expensive

https://web.archive.org/web/20090912001114/http://blogs.sun.com/jonathan/
6•_RPM•30m ago•1 comments

Hardest AI Benchmark – Enkokilish

https://enkokilish-bench.vercel.app/
2•dagmawibabi•30m ago•1 comments

National Security Strategy Document Revives Monroe Doctrine, Slams Europe

https://www.reuters.com/business/finance/trump-strategy-document-revives-monroe-doctrine-slams-eu...
2•petethomas•31m ago•0 comments

NeocloudX: Trade Compute as a Commodity

https://neocloudx.com
1•jack_nclx•32m ago•1 comments

Show HN: Kiwi Notes – Simple audio-powered vocabulary app

https://app.copiaviva.com/
1•hussein-khalil•32m ago•1 comments

National parks drops fee-free MLK Day, Juneteenth day; adds Trump's birthday

https://www.npr.org/2025/12/06/g-s1-101090/national-parks-fee-free-calendar-mlk-juneteenth
2•stopbulying•32m ago•1 comments

Show HN: My first open source project called Claude Code Splitter

https://github.com/theaustinhatfield/claude-code-splitter
1•AustinHatfiel•33m ago•1 comments

Polynomial roots visualisation inspired by 2swap's video on the quintic

https://github.com/TheRealOrange/acidvis
3•birdculture•36m ago•0 comments

Show HN: Zen

https://github.com/HakAl/zen
1•UmGuys•37m ago•0 comments

Quantum theory does not need complex numbers

https://arxiv.org/abs/2504.02808
1•QueensGambit•39m ago•0 comments

Trains cancelled over fake bridge collapse image

https://www.bbc.com/news/articles/cwygqqll9k2o
20•josephcsible•41m ago•9 comments

CME Data Center Outage Caused by Human Error, CyrusOne Says

https://www.bloomberg.com/news/articles/2025-12-06/cme-data-center-outage-caused-by-human-error-c...
2•toomuchtodo•43m ago•2 comments

11-year-old named Guinness World Record holder for youngest video game dev

https://www.bbc.com/news/articles/c17p4prj8qgo
2•starkparker•48m ago•0 comments

The Physics of Semiconductors [pdf]

http://www.physics.gov.az/book_P/Phys_Semic_Grundmann.pdf
1•aabiji•48m ago•1 comments