frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

The Internet Used to Feel Smaller

https://tqs.bearblog.dev/the-internet-used-to-feel-smaller/
1•speckx•2m ago•0 comments

Find first 100 users on Reddit

1•redleadsapp•2m ago•0 comments

RPCS3 says "learn to code" as it bans (fully) AI-generated pull requests

https://www.neowin.net/news/rpcs3-says-learn-to-code-as-it-bans-ai-agents-from-project/
1•bundie•4m ago•0 comments

The Agent Stack Was Designed for the Wrong Workload

https://rmmod.com/posts/agent/agenticos-workshop/
1•guanlan•4m ago•0 comments

Amazon to stop selling 'hooligan e-bikes' in California

https://electrek.co/2026/05/11/amazon-to-stop-selling-hooligan-bikes-in-california-after-investig...
1•harambae•5m ago•0 comments

IP over Avian – The informal report from the RFC 1149 event

https://blug.linux.no/rfc1149/writeup/
1•moebrowne•5m ago•0 comments

Victory after a decade preventing Radio Lockdown

https://fsfe.org/news/2026/news-20260430-01.de.html
1•mkesper•5m ago•0 comments

Stop Writing YAML: Configuring ML Systems with Confingy

https://runwayml.com/news/stop-writing-yaml-configuring-ml-systems-with-confingy
1•nielka•5m ago•0 comments

Fragile Connectedness in Caregiver-Adolescent Relationships Confers Risk

https://onlinelibrary.wiley.com/doi/10.1111/famp.70131
2•PaulHoule•6m ago•0 comments

Half-assing it with everything you've got

https://mindingourway.com/half-assing-it-with-everything-youve-got/
2•syabro•7m ago•0 comments

A Field Guide to Learning

https://brianschrader.com/archive/a-field-guide-to-learning/
2•sonicrocketman•7m ago•1 comments

The Courtroom Circus with Elon Musk and Sam Altman

https://www.nytimes.com/2026/05/11/technology/courtroom-circus-elon-musk-sam-altman.html
1•1vuio0pswjnm7•8m ago•0 comments

Canvas got hacked, provost banned exams, professor responded by assigning Hayek

https://old.reddit.com/r/UIUC/comments/1ta8b3o/i_opened_my_email_expecting_exam_postponed_hang/
1•jdcampolargo•8m ago•0 comments

YSK: The Register is doing some report on Gemini API Key Compromises

https://old.reddit.com/r/googlecloud/comments/1ta5sim/comment/ol7a1pr/
1•crazysim•9m ago•1 comments

Ask HN: How often do you investigate issues in production vs. looking at logs?

1•aspectrr•9m ago•0 comments

OfficeOS: Open-source infrastructure for scaling and managing AI agents

https://github.com/officeos-co/officeos
1•Harro123•10m ago•0 comments

Facts and Fiction: Stories Stripped Away by Book Bans

https://pen.org/report/facts-fiction/
1•ChrisArchitect•11m ago•0 comments

Learning on the Shop Floor

https://simonwillison.net/2026/May/11/learning-on-the-shop-floor/
2•swolpers•11m ago•0 comments

Geometry of the cumulant series in diffusion MRI

https://www.nature.com/articles/s41467-026-70018-w
1•bookofjoe•13m ago•0 comments

When Will Early Startup Employees Get Their Fair Share?

https://www.lesecretairedefernand.co/en/entrepreneurship/can-startups-share-value-more-fairly-wit...
1•lbdremy•13m ago•0 comments

Dirty Frag is a new Linux bug putting your PC at risk and there's no easy fix

https://www.zdnet.com/article/dirty-frag-new-linux-bug-system-at-risk-no-easy-fix/
2•CrankyBear•14m ago•0 comments

Pilot (Proramming Language)

https://en.wikipedia.org/wiki/PILOT
1•BruceEel•16m ago•0 comments

Meta's Hyperagents and Self-Correcting Agents

https://jdsemrau.substack.com/p/hyperagents-and-self-correcting-systems
1•Brajeshwar•18m ago•0 comments

Show HN: Zot coding agent now supports DeepSeek

https://www.zot.sh/#about
4•patriceckhart•19m ago•0 comments

Success Metric Is the Hammer

https://hooda.xyz/blog/success-metric-is-the-hammer/
1•hooda•19m ago•0 comments

A Software Engineer's Guide to Predictable Home Espresso

https://medium.com/@rupaj.soni/stop-buying-expensive-espresso-machines-and-other-unsolicited-advi...
1•rupajs•20m ago•0 comments

Microsoft denies Win 11 CPU boost is lazy, says Apple does it and you love it

https://www.windowslatest.com/2026/05/11/microsoft-denies-windows-11-cpu-boost-trick-is-a-lazy-fi...
3•pzxc•21m ago•0 comments

Show HN: The Extensions Scraping Your AI Chats

https://amibeingpwned.com/blog/ai-chat-scraper-wall-of-shame
1•acorn221•21m ago•0 comments

Preserving Fisher-Price Pixter

https://dmitry.gr/?proj=37.%20Pixter&r=05.Projects
1•dmitrygr•22m ago•0 comments

A Technical Guide to Compiling Emacs for Performance on Linux and Unix Systems

https://www.jamescherti.com/compiling-emacs/
1•signa11•23m ago•0 comments