frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Porsche Restored This 20-Year-Old Carrera GT to 'Zero-Kilometer Condition'

https://www.thedrive.com/news/porsche-restored-this-20-year-old-carrera-gt-to-zero-kilometer-cond...
1•PaulHoule•1m ago•0 comments

We built a free cross-app AI assistant inspired by what Apple Intelligence

https://www.gethelios.xyz/
1•rogermas•2m ago•1 comments

Show HN: A WebGPU-based browser engine with "Blam "-style physics

1•goovbot•3m ago•0 comments

WP-Bench: A WordPress AI Benchmark

https://make.wordpress.org/ai/2026/01/14/introducing-wp-bench-a-wordpress-ai-benchmark/
1•chilipepperhott•8m ago•0 comments

The Cost of PostgreSQL Arrays

https://boringsql.com/posts/good-bad-arrays/
2•birdculture•9m ago•0 comments

General Availability for GitLab Duo Agent Platform

https://about.gitlab.com/blog/gitlab-duo-agent-platform-is-generally-available/
3•HieronymusBosch•11m ago•0 comments

Ring subscriptions mistakenly issue unexpected charges for the entire users base

https://piunikaweb.com/2026/01/15/ring-unexpected-ai-pro-charges/
2•artyom•13m ago•1 comments

The Daily Standup Is Broken: Why Modern Dev Teams Need a Reset

https://deadlocked.life/blog/standups-broken/
1•cebert•14m ago•0 comments

Musk Updates Starlink to Beat Iran's 'Kill Switch'–Makes It Free

https://www.forbes.com/sites/zakdoffman/2026/01/14/musk-updates-starlink-to-beat-irans-kill-switc...
4•Imustaskforhelp•18m ago•0 comments

Elon Musk's Grok 'Undressing' Problem Isn't Fixed

https://www.wired.com/story/elon-musks-grok-undressing-problem-isnt-fixed/
2•ceejayoz•18m ago•0 comments

Show HN: I built a 3D web-based multiplayer game with Claude Code

https://arena.ibuildstuff.eu
1•tombuildsstuff•22m ago•2 comments

The origin of the names of the days of the week in Portuguese

https://www.practiceportuguese.com/learning-notes/days-of-the-week/
2•DamonHD•22m ago•1 comments

European troops arrive in Greenland to boost the Arctic island's security

https://www.npr.org/2026/01/15/g-s1-106113/european-troops-arrive-greenland
5•geox•22m ago•0 comments

Using Git to attribute AI-generated code

https://github.com/mesa-dot-dev/agentblame
3•remolacha•27m ago•2 comments

Proof of Concept to Test Humanoid Robots

https://thehumanoid.ai/humanoid-and-siemens-completed-a-proof-of-concept-to-test-humanoidrobots-i...
1•0xedb•28m ago•0 comments

One Guy Crowdsourced More Than 500 Dashcams for Minneapolis to Film ICE

https://www.404media.co/how-one-guy-crowdsourced-more-than-500-dashcams-for-minneapolis-to-film-ice/
1•colinprince•29m ago•0 comments

OpenAI Partners with Cerebras

https://www.cerebras.ai/blog/openai-partners-with-cerebras-to-bring-high-speed-inference-to-the-m...
2•nezhar•29m ago•2 comments

Show HN: Turn GitHub Contributions Graph into Space Shooter Battle Field

https://github.com/czl9707/gh-space-shooter
1•zane__chen•32m ago•0 comments

Sony wiped over 1k shovelware games off the PlayStation store without warning

https://www.eurogamer.net/sony-wiped-over-1000-shovelware-games-off-the-playstation-store-without...
5•croes•34m ago•0 comments

Playing daily games at work? Timdle just launched work mode

https://www.timdle.com/work
2•maskinberg•35m ago•0 comments

Context Engineering for Personalization with OpenAI Agents SDK

https://cookbook.openai.com/examples/agents_sdk/context_personalization
1•gmays•35m ago•0 comments

When programs assume the system will never change, episode 4: Stealing strings

https://devblogs.microsoft.com/oldnewthing/20260115-00/?p=111988
3•zdw•37m ago•0 comments

I added partial (incomplete) row streaming to a query engine

https://blog.vega.io/posts/partial_stream/
1•tontinton•39m ago•0 comments

Al models were given four weeks of therapy: the results worried researchers

https://www.nature.com/articles/d41586-025-04112-2
2•simonebrunozzi•41m ago•1 comments

State and Federal Lawmakers Want Data Centers to Pay More for Energy

https://www.nytimes.com/2026/01/15/business/energy-environment/data-center-energy-electricity-cos...
1•donohoe•41m ago•0 comments

US suspends immigrant visa processing for 75 countries beginning January 21

https://travel.state.gov/content/travel/en/News/visas-news/immigrant-visa-processing-updates-for-...
1•mportela•42m ago•1 comments

Ask HN: Is Claude Code bad for ADHD?

3•chriswright1664•43m ago•2 comments

Show HN: TeletextSignals – Local RAG over 25 Years of Swiss Teletext News

https://github.com/r-follador/TeletextSignals
1•folli•44m ago•0 comments

TWC Security Party – Group education event for tech workers to improve their PR

https://us02web.zoom.us/meetings/83864945846/invitations?signature=4UIf8C8zlkKWDox7ZdErZvL2DhcwC8...
1•todsacerdoti•45m ago•0 comments

Using Tokio with CPU-Bound Tasks in Rust (2022)

https://www.influxdata.com/blog/using-rustlangs-async-tokio-runtime-for-cpu-bound-tasks/
1•Abbit•49m ago•0 comments