frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Don't give away to the gradient descent

https://carteakey.dev//blog/dont-give-away-to-the-gradient-descent/
1•carteakey•26s ago•0 comments

Shell and Skills and Compaction: Tips for long-running agents that do real work

https://developers.openai.com/blog/skills-shell-tips/
1•vinhnx•27s ago•0 comments

Anna's Archive 'Releases' Spotify Tracks, Despite Legal Pushback

https://torrentfreak.com/annas-archive-quietly-releases-millions-of-spotify-tracks-despite-legal-...
2•pabs3•6m ago•0 comments

Terms of Service

https://felix.dognebula.com/art/terms-of-service.html
1•luu•6m ago•0 comments

Healthcare Jobs Have Become the Engine of America's Labor Market

https://www.wsj.com/economy/jobs/healthcare-jobs-have-become-the-engine-of-americas-labor-market-...
1•petethomas•11m ago•0 comments

Benchmarking 8 remote browser providers with 250 concurrent AI agents

https://research.aimultiple.com/remote-browsers/
1•toliveistobuild•12m ago•1 comments

A language model made in Latin America, for Latin America

https://www.latamgpt.org/en
2•ofou•13m ago•1 comments

SpaceX Makes a Pivot, Wants to Build on the Moon Instead

https://www.universetoday.com/articles/spacex-makes-a-huge-pivot-wants-to-build-on-the-moon-instead
1•geox•13m ago•0 comments

Building Chess in about 350 lines of Clojure

https://www.sammystraus.com/#building-chess-in-about-350-lines-of-clojure
1•sammy0910•13m ago•0 comments

Show HN: Claude Remote

https://github.com/jamierpond/claude-remote
2•jamiepond•14m ago•2 comments

I found a way to reduce context redundancy 30-60%

https://www.triage-sec.com/blog/delta-ltsc
1•nicksec•15m ago•0 comments

Show HN: IQT – Why space feels panoramic and time feels fleeting

https://github.com/creatorrr/intrinsic-quality-theory
1•diwank•16m ago•0 comments

Mistral's revenues soar over $400M as Europe seeks AI independence

https://www.ft.com/content/664249e7-e8d5-4425-b397-ad3ed590b305
1•petethomas•17m ago•0 comments

Ask HN: What resources do you use to fill specialized positions?

1•jasbur•19m ago•0 comments

US payment processor BridgePay outage lasts a week due to ransomware attack

https://www.bleepingcomputer.com/news/security/payments-platform-bridgepay-confirms-ransomware-at...
3•echo7394•22m ago•0 comments

How Do You Patch This? Red Team Down

https://github.com/moketchups/permanently-jailbroken
1•MoKetchups•22m ago•0 comments

Hyperliquidity Provider (HLP)

https://app.hyperliquid.xyz/vaults/0xdfc24b077bc1425ad1dea75bcb6f8158e10df303
2•andxor•23m ago•0 comments

We Bought the First Fake Toyota from China [video]

https://www.youtube.com/watch?v=_uoCadOum-A
1•JojoFatsani•23m ago•0 comments

Apple reportedly pushing back Gemini-powered Siri features beyond iOS 26.4

https://9to5mac.com/2026/02/11/apple-reportedly-pushing-back-gemini-powered-siri-features-beyond-...
3•doctoboggan•25m ago•0 comments

The Problem with LLMs

https://www.deobald.ca/essays/2026-02-10-the-problem-with-llms/
1•vinhnx•28m ago•0 comments

The Dark Side of This AI Startup's Super-Fast Growth

https://www.forbes.com/sites/rashishrivastava/2026/02/11/racist-videos-and-payment-problems-the-d...
2•echelon•29m ago•1 comments

Deriving the Fisher Equation from 2D Fluid Dynamics (SSRN)

https://ssrn.com/abstract=6152150
1•alex_w_systems•30m ago•0 comments

Mathematicians Are Putting A.I. To the Test

https://www.nytimes.com/2026/02/07/science/mathematics-ai-proof-hairer.html
1•sonabinu•33m ago•0 comments

Russia blocks Meta's WhatsApp messaging service

https://www.ft.com/content/468ebeec-3d38-4f8c-8513-97f533d8f43b
1•petethomas•35m ago•0 comments

Without XSLT, user is prompted to download RSS in browser [video]

https://www.youtube.com/watch?v=YxfUwbliilQ
2•mijustin•36m ago•0 comments

What Mamdani Doesn't Know About Tenants

https://www.theatlantic.com/ideas/2026/02/mamdani-tenant-organizing-affordable-housing/685951/
2•fortran77•36m ago•1 comments

Windsurf Arena Mode Leaderboard: The People Want Speed

https://windsurf.com/blog/windsurf-arena-mode-leaderboard
2•swyx•36m ago•1 comments

Michael Green discusses Bitcoin [video]

https://www.youtube.com/watch?v=6eFKqTg6GS4
1•thomassmith65•37m ago•0 comments

Apple's Creator Studio Usage Restrictions

https://arstechnica.com/gadgets/2026/01/seven-things-to-know-about-how-apples-creator-studio-subs...
1•colinprince•38m ago•0 comments

Singapore spent 11 months booting China-linked snoops out of telco networks

https://www.theregister.com/2026/02/10/singapore_telco_espionage/
1•cwwc•38m ago•0 comments