frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Routing vs. trust in multi-agent systems

https://www.godaddy.com/resources/news/intelligent-ai-routing
1•tmuhlestein•1m ago•0 comments

Show HN: Vizier – A physical design advisor for DuckDB

1•habedi0•1m ago•0 comments

Building FireStriker: Why I'm Making Civic Tech Free

https://firestriker.com/blog/building-firestriker-why-im-making-civic-tech-free
1•blakeofwilliam•2m ago•0 comments

OTEL/EDOT AutoPilot – OpenTelemetry for all languages (skills and MD files)h

https://github.com/gmoskovicz/edot-autopilot
1•gmoskovicz•2m ago•1 comments

Damaged church floor may have revealed the grave of the fourth musketeer

https://arstechnica.com/science/2026/03/archaeologists-may-have-found-the-grave-of-the-legendary-...
1•Khaine•4m ago•0 comments

Trust Signals as Sparklines for Hacker News

https://hn-trustspark.com/
1•solaire_oa•4m ago•0 comments

Google Analytics MCP for Claude

https://github.com/googleanalytics/google-analytics-mcp
1•crog•6m ago•0 comments

Church attendance report pulled after YouGov finds 'fraudulent' responses

https://www.bbc.com/news/articles/cpwjxx5eyn1o
1•dijksterhuis•6m ago•1 comments

You're Not Getting Promoted Because You're Doing Your Job

https://www.pathtostaff.com/p/youre-not-getting-promoted-because
1•sidwyn•7m ago•0 comments

Create a Dedicated Focus Nook

https://practicalbetterments.com/create-a-dedicated-focus-nook/
1•DitheringIdiot•8m ago•0 comments

Review of "Vibe Coding: Building production grade software with Gen AI"

https://www.pramodb.com/index.php/2026/03/26/book-review-vibe-coding-building-production-grade-so...
1•pramodbiligiri•9m ago•0 comments

Cohere launches an open source voice model specifically for transcription

https://techcrunch.com/2026/03/26/cohere-launches-an-open-source-voice-model-specifically-for-tra...
1•newusertoday•10m ago•0 comments

Show HN: Grandma Knows – conversational web analytics

https://grandmaknows.com/
1•sergeigolubev•12m ago•1 comments

Wikipedia bans AI-generated articles

https://www.theverge.com/tech/901461/wikipedia-ai-generated-article-ban
2•thm•13m ago•0 comments

CISA's chief warns shutdown is increasing cyber risks, causing resignations

https://therecord.media/cisa-acting-chief-warns-shutdown-increasing-risks-leading-to-retention-is...
1•speckx•14m ago•1 comments

Engineered E. Coli for Co-Production of Lignocellulosic Ethanol and PHB

https://www.mdpi.com/2076-2607/14/3/537
1•PaulHoule•14m ago•0 comments

Nacodex – Open-Source/Contribution Coding Architecture Codex

https://nacodex.pukapasoft.xyz/
1•ondrejdvorak•15m ago•0 comments

AI has the worst sales pitch I've ever seen

https://www.noahpinion.blog/p/ai-has-the-worst-sales-pitch-ive
2•ray__•16m ago•1 comments

Prompt Engineering Is Not. Engineering, That Is

https://the-infrastructure-mindset.ghost.io/prompt-engineering-is-not/
2•wphillipmoore•18m ago•0 comments

Creating new Python webframework –SlimeWeb

https://pypi.org/project/SlimeWeb/
1•Abilash_Suresh•18m ago•0 comments

New record: Laser for surgery cuts bone deeper than before

https://medicalxpress.com/news/2026-02-laser-surgery-bone-deeper.html
1•PaulHoule•19m ago•0 comments

Let's Standardize the 1970 Epoch

https://github.com/billpg/1970EpochalTime/
1•billpg•19m ago•0 comments

AI-Driven Offensive Security: The Current Landscape and What It Means

https://www.praetorian.com/blog/ai-driven-offensive-security/
1•tcbrah•20m ago•0 comments

Colorado River crisis: headwater states resist cuts, citing scarce supply

https://wyofile.com/amid-dire-situation-for-colorado-river-basin-headwater-states-say-they-cant-c...
3•toomuchtodo•20m ago•1 comments

NimbiCMS – a Markdown-first CMS for static servers

2•abel_vm•20m ago•0 comments

What's the biggest business you could run alone?

https://orischwartz.com/posts/whats-the-biggest-business-you-could-run-alone.html
1•fleaflicker•21m ago•0 comments

Intercom's model beats GPT 5.4 and Sonnet 4.6 at customer support resolutions

https://venturebeat.com/technology/intercoms-new-post-trained-fin-apex-1-0-beats-gpt-5-4-and-clau...
1•bscanlan•24m ago•0 comments

Refusal to Give the Govt Passwords to Personal Mobile Criminalized in Hong Kong

https://hk.usconsulate.gov/security-alert-2026032601/
3•jmsflknr•24m ago•0 comments

Development of 3D-printed chitosan/p-coumaric acid scaffolds for wound healing

https://www.sciencedirect.com/science/article/pii/S0939641125003315
3•PaulHoule•25m ago•0 comments

Gratitude Without God

https://www.theatlantic.com/health/archive/2014/11/the-phenomenology-of-gratitude/383174/
1•amadeuspagel•26m ago•2 comments