frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Is the World Random?

https://mantrna.com/astrobench
1•prabhatkr•52s ago•0 comments

Show HN: 30min video analysis for $0.003 via frame-tiling and Vision API

https://github.com/unhaya/vam-seek-ai
1•haasiy•3m ago•0 comments

300X fast clustering with rust-louvain for nodes

https://github.com/FastBuilderAI/rust-louvain
1•prabhatkr•4m ago•0 comments

Quantum Name Service (QNS)- Path to Web5

https://github.com/aevov/qns
1•cr8oscloud•6m ago•1 comments

Show HN: vr.dev – simple 3D/VR/XR portfolio and links (Meta hit hard this week)

https://www.vr.dev/
1•vrdev•6m ago•0 comments

Shackleton and the Endurance Expedition: Photos from the 1915 Disastrous Journey

https://www.utterlyinteresting.com/post/the-amazing-survival-story-of-ernest-shackleton-and-his-e...
1•nomagicbullet•7m ago•1 comments

Show HN: Task Orchestrator – Production Safety for Claude Code Agents

https://github.com/TC407-api/task-orchestrator
1•Travis_Cole•8m ago•1 comments

Model is intended for use particularly for language learning

https://huggingface.co/EnversonAI/DeepSeek-R1-FineTuned-AdaptiveQGen-COT
1•AslanMammadli•23m ago•1 comments

Ask HN: Is repalcing an enterprise product with LLMs a realistic strategy?

1•chandmk•23m ago•0 comments

Pushing the smallest possible change to production

https://ankursethi.com/blog/smallest-possible-change/
1•GeneralMaximus•24m ago•0 comments

Why Xcode's AI Writes Better SwiftUI Than Claude Code, Codex

https://www.ameyalambat.com/blog/swiftui-skills
1•ameyalambat128•26m ago•0 comments

Show HN: Open-Source DLP for LLMs

https://github.com/dorcha-inc/ceil-dlp
1•unclecolm•29m ago•0 comments

Cursor AI refusing $20 refund after 3 days of broken service

1•Waldopro•29m ago•0 comments

Show HN: Monitor Claude/Codex usage on Linux via browser cookies (no API keys)

https://github.com/NihilDigit/waybar-ai-usage
1•NihilDigit•32m ago•1 comments

Spectrum Brings NBA Games in Apple Immersive to Apple Vision Pro

https://www.apple.com/newsroom/2025/10/spectrum-brings-nba-games-in-apple-immersive-to-apple-visi...
1•Austin_Conlon•34m ago•0 comments

Crypto holder loses $283M to scammer impersonating wallet support

https://bsky.app/profile/web3isgoinggreat.com/post/3mcn26h32wp2q
4•unforgivenpasta•39m ago•1 comments

AI-Powered Diabetes Analysis with GitHub Copilot and Claude Skills [video]

https://www.youtube.com/watch?v=on5R6PWj8Wg
4•shanselman•42m ago•0 comments

No Chess on a Dead Planet

https://indianexpress.com/article/sports/chess/climate-activists-protests-hold-up-tata-steel-ches...
1•akbarnama•43m ago•0 comments

Show HN: Vanslist – Craigslist for tech freelancers, no fees

https://vanslist.com
1•netgeniuskid•44m ago•0 comments

Show HN: Turkish Sieve Engine – GPU-Accelerated Prime Number Generator

https://github.com/bilgisofttr/turkishsieve
1•bilgisoft•45m ago•0 comments

Tell HN: Google Trust and Safety is a joke

2•tokyobreakfast•51m ago•1 comments

The relentless rule of my fitness tracker

https://timharford.com/2025/10/the-relentless-rule-of-my-fitness-tracker/
7•Arnt•1h ago•1 comments

Aldrich Ames built a career on betraying trust

https://www.economist.com/obituary/2026/01/15/aldrich-ames-built-a-career-on-betraying-trust
1•petethomas•1h ago•0 comments

Show HN: macOS Screenshot Organizer

https://www.shotsnap.ai/
2•libiny•1h ago•0 comments

'We'll Sue': White House's Warning to CBS Is Sign of a New Media Status Quo

https://www.nytimes.com/2026/01/17/business/media/cbs-news-trump-interview.html
2•stopbulying•1h ago•2 comments

jQuery 4.0.0 Released

https://blog.jquery.com/2026/01/17/jquery-4-0-0/
32•OuterVale•1h ago•5 comments

SkillHub – NPM for AI agent rules, share team standards across 13 AI tools

https://github.com/cloudvalley-tech/skillhub
1•zxh•1h ago•1 comments

Show HN: StarFetch – A lightweight, modern system fetch tool in Rust

https://github.com/Linus-Shyu/StarFetch_Core
1•LinusShyu•1h ago•1 comments

Show HN: Intuitive TUI for Ghostty Terminal Configuration

https://github.com/intaek-h/ghofig
1•intaek•1h ago•0 comments

Show HN: A self-custody medical records prototype (lessons learned)

https://github.com/Mzhvnn-tch/sehati-apps
1•SERSI-S•1h ago•1 comments