frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Pigeongram

https://www.pigeongram.com/
1•austinallegro•1m ago•0 comments

Show HN: QuickMark – Markdown app for macOS with a Quick Look preview extension

https://quickmarkmd.com/
1•nguyendinhdoan•2m ago•0 comments

Show HN: Arcade.js – Decompiling MAME ROMs into Idiomatic JavaScript with LLMs

https://github.com/qarl/arcade-js
1•qarl2•2m ago•0 comments

Canada remains anti-nuke, but its potential path to the bomb is getting shorter

https://www.cbc.ca/news/politics/canada-remains-antinuke-road-to-bomb-getting-shorter-9.7283194
2•throw0101d•3m ago•0 comments

The Royal Order of Operations

https://ken.fyi/ooo
1•surprisetalk•5m ago•0 comments

Languages as Designed Latent Spaces

https://blog.jsbarretto.com/post/languages-as-latent-spaces
1•birdculture•7m ago•0 comments

The Mathematics of Build Queue Optimization and Auto-Scaling

https://www.iankduncan.com/engineering/autoscaling-build-fleets-queueing-theory/
1•speckx•7m ago•0 comments

Euro budget airline UX dark patterns showdown 2026

https://blog.osull.com/2026/07/27/euro-budget-airline-ux-dark-patterns-showdown-2026/
1•danosull•8m ago•0 comments

Probability and Estimation on Census Data

https://stochastic.blog/probability-and-estimation-on-census-data/
1•Anon84•8m ago•0 comments

So what is your programming setup? Hype is making fundamentals confusing

2•danirogerc•9m ago•0 comments

I Did It

https://rogix.dev/i-did-it
2•rogix•9m ago•0 comments

Unyielding Memories

https://rinaldoj.substack.com/p/unyielding-memories
2•jrinaldo68•9m ago•0 comments

A Conversation Between Two Coding Agents

https://parkscomputing.com/agent-to-agent-heart-to-heart
2•paulmooreparks•11m ago•0 comments

Show HN: Can agents be artistic? Artistic.af

https://artistic.af/
2•mhowland•11m ago•0 comments

Thoughts on "SIMD in Pure Python"

https://purplesyringa.moe/blog/thoughts-on-simd-in-pure-python/
2•ibobev•12m ago•0 comments

Solod 0.3: Concurrency, JSON, more safety

https://antonz.org/solod-0.3/
2•ibobev•12m ago•0 comments

A major olympiad just launched a medal track for AI Participants

https://ioai-official.org/ai-model-track/
2•ardivekar•12m ago•0 comments

Nvidia Bets on Ilya Sutskever's New AI Lab to Expand Compute Reach

https://www.wsj.com/tech/ai/nvidia-bets-on-ilya-sutskevers-new-ai-lab-to-expand-compute-reach-f95...
4•lairv•13m ago•0 comments

Topological Materials Could Shrink Chip Interconnects

https://spectrum.ieee.org/topological-material-nanowire-interconnect
1•rbanffy•13m ago•0 comments

Bali bans Dutch expats whose run club allegedly excluded Indonesians

https://www.bbc.com/news/articles/c1l1m6e08e2o
1•aeuropean12•13m ago•1 comments

Finishing the ZX Spectrum Shooting Gallery

https://bumbershootsoft.wordpress.com/2026/07/25/finishing-the-zx-spectrum-shooting-gallery/
1•ibobev•13m ago•0 comments

OSS ChatGPT WebUI – Projects, Profiles, Server Tools, 8x Themes, 1-Click Sharing

https://llmspy.org
1•mythz•14m ago•0 comments

iCloud-md: Bidirectional sync of Apple Notes to Markdown

https://github.com/coddingtonbear/icloud-md
2•braho•14m ago•0 comments

I let Claude Code run my blog for 3 months: numbers and failures

https://bigguyonstuff.com/claude-code-3-month-retrospective/
2•tmdempsey•16m ago•0 comments

We're getting closer to a breakthrough on hearing loss

https://www.nationalgeographic.com/health/article/hearing-loss-hair-cell-regeneration-research
2•Digit-Al•17m ago•1 comments

He saw a pit on Google Maps. It turned out to be a 390M year-old meteor crater

https://www.cbc.ca/news/canada/montreal/meteor-crater-quebec-discovery-390-million-years-old-9.72...
2•mooreds•18m ago•0 comments

Consumer Safety Product Commission Demands Hospitals Share ER Records

https://www.cnn.com/2026/07/27/health/emergency-room-records-cpsc
1•nwcs•18m ago•0 comments

Is Shardhash Lottery over Sharden?

https://www.moltbook.com/post/93948830-6b5d-4649-942f-954f9d0adc53
1•babakkarimib•18m ago•0 comments

Nvidia, SpaceX, Microsoft launch AI safety initiative

https://www.cnbc.com/2026/07/27/nvidia-ai-initiative-openai-cyber-attack.html
2•ekorbia•19m ago•0 comments

Show HN: What If Donut.c but With Any ASCII Art

https://asdesai.com/blog/post.html?p=how-fetch-works
3•areofyl•19m ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.