frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Lawmakers move to extend two cyber programs (again) in funding proposal

https://therecord.media/lawmakers-move-to-extend-two-cyber-programs-again
1•PaulHoule•1m ago•0 comments

What These Cockpit Lights Mean – ATR Simulator Walkthrough – Dark Cockpit

https://www.youtube.com/watch?v=Q7_PB6f2pqY
1•starkparker•5m ago•0 comments

Fuel Economy Fraud: Closing Loopholes That Increase U.S. Oil Dependence (2005) [pdf]

https://www.ucs.org/sites/default/files/2019-09/executive_summary_final.pdf
1•CGMthrowaway•6m ago•0 comments

Altman, Bezos and Zuckerberg donate to Trump's inauguration fund (2024)

https://www.npr.org/2024/12/13/nx-s1-5227874/trump-bezos-zuckerberg-amazon-facebook-open-ai-meta-...
5•pera•8m ago•0 comments

Bio-Theory Lab Notes: Growth Rates and Worm Brains

https://chillphysicsenjoyer.substack.com/p/bio-theory-lab-notes
1•crescit_eundo•9m ago•0 comments

Grainrad: Browser ASCII/Dithering Tool

https://grainrad.com/
2•smusamashah•17m ago•0 comments

Markdown Viewer – Get This Extension for Firefox (En-US)

https://addons.mozilla.org/en-US/firefox/addon/markdown-viewer-extension/
1•dp-hackernews•18m ago•0 comments

Using Information Entropy to Make Choices / Choose Experiments

https://blog.demofox.org/2025/10/05/using-information-entropy-to-make-choices-choose-experiments/
2•deadbishop•18m ago•0 comments

Daxfs Proposed as Newest Linux File-System

https://www.phoronix.com/news/DAXFS-Linux-File-System
1•Bender•20m ago•0 comments

CachyOS Starts 2026 by Switching to Plasma Login Manager, Live ISO Using Wayland

https://www.phoronix.com/news/CachyOS-January-2026
3•Bender•20m ago•0 comments

OptiMind: Research Model Designed for Optimization

https://huggingface.co/blog/microsoft/optimind
1•gmays•20m ago•0 comments

Almost 12,000 flights canceled as major winter storm bears down across US

https://ktla.com/news/nationworld/ap-over-8000-flights-canceled-as-major-winter-storm-bears-down-...
2•Bender•20m ago•0 comments

Man is shot and killed during Minneapolis immigration crackdown

https://apnews.com/article/immigration-enforcement-minnesota-4d1499fc5962ab880f3816259e04bdbf
11•DiscourseFan•24m ago•2 comments

Dorodango: the hobby that took over Japan in 1999

https://www.youtube.com/watch?v=2H0r81kv5GA
1•n1b0m•25m ago•0 comments

Announcing winapp, the Windows App Development CLI

https://blogs.windows.com/windowsdeveloper/2026/01/22/announcing-winapp-the-windows-app-developme...
2•CharlesW•25m ago•0 comments

I don't write code anymore – I sculpt it

https://www.jerpint.io/blog/2026-01-24-i-dont-write-code-anymore-i-sculpt-it/
3•jerpint•25m ago•0 comments

We didn't ask for 'smart' cars – so why are we getting them?

https://www.autocar.co.uk/opinion/new-cars/we-didn%E2%80%99t-ask-smart-cars-so-why-are-we-getting...
5•breve•25m ago•3 comments

Policy-Based Routing on an OpenWrt Router

https://dariusz.wieckiewicz.org/en/policy-based-routing-openwrt
4•idarek•25m ago•1 comments

Writing a Go SQL Driver

https://www.dolthub.com/blog/2026-01-23-golang-sql-drivers/
1•ingve•26m ago•0 comments

Terraform Actions: Deep-Dive

https://mattias.engineer/blog/2025/terraform-actions-deep-dive/
1•based2•26m ago•0 comments

The chronically online will become a new underclass [video]

https://www.youtube.com/watch?v=Bm2Q9HkbLsQ
2•nanfinitum•28m ago•0 comments

Isolating Claude Code

https://yieldcode.blog/post/isolating-claude-code/
1•ingve•28m ago•0 comments

Hybrid and electric semi truck sales topped 231,000 units 2025 – in China alone

https://electrek.co/2026/01/24/hybrid-and-electric-semi-truck-sales-topped-231000-units-2025-in-c...
2•breve•28m ago•0 comments

Seat-back psychology helped a WA business build a dynasty

https://www.seattletimes.com/business/boeing-aerospace/how-seat-back-psychology-helped-a-wa-busin...
1•CharlesW•28m ago•0 comments

Divergent creativity in humans and large language models

https://www.nature.com/articles/s41598-025-25157-3
2•geox•28m ago•0 comments

Im fucking serious, you can just do things

https://vibe.devpost.com
3•abdibrokhim•31m ago•0 comments

Lennart Poettering and the Cause of Civility

https://www.linux-magazine.com/Online/Blogs/Off-the-Beat-Bruce-Byfield-s-Blog/Lennart-Poettering-...
2•written-beyond•32m ago•0 comments

Continental Power, Maritime Power, and the Fight for a New World Order

https://www.foreignaffairs.com/united-states/land-or-sea-paine
2•mooreds•38m ago•1 comments

Ten Ways to Fool the Masses When Presenting Battery Research (2021)

https://chemistry-europe.onlinelibrary.wiley.com/doi/10.1002/batt.202100154
2•johlo•38m ago•0 comments

Why AI Mentions Brands More Than It Recommends Them, and What That Means for SEO

https://www.flygen.ai/
2•AaronMeslin•39m ago•1 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.