frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Codex Pricing: Pro has unlimited 5.6 usage

https://chatgpt.com/codex/pricing/
1•rene_d•1m ago•0 comments

DepthFirst: Continuous Cyber Defense

https://depthfirst.com/
1•handfuloflight•1m ago•0 comments

The $170B lesson data center developers keep learning the hard way

https://www.fastcompany.com/91612143/ai-data-centers-local-communities
1•johnshades•1m ago•0 comments

16-year-old found Microsoft bug, got admin access to 17.3T-row databases

https://www.theregister.com/security/2026/09/30/16-year-old-researcher-found-a-microsoft-bug-got-...
2•johnshades•3m ago•0 comments

Gloriously project runs transformer model written in PDP-11 assembly [video]

https://www.youtube.com/watch?v=OUE3FSIk46g
1•madradavid•5m ago•0 comments

Strata: Run a 125B-parameter AI model on a normal gaming PC

https://github.com/Niko1221/Strata
1•maille•7m ago•0 comments

Hackers stole US Military records during months-long data breach

https://techcrunch.com/2026/09/30/hackers-stole-millions-of-us-military-personnel-records-during-...
1•DamnInteresting•8m ago•0 comments

There Are Plenty of Laws on the Books to Check the A.I. Giants. Use Them

https://www.nytimes.com/2026/09/30/opinion/ai-anthropic-amodei-self-regulation.html
2•SLHamlet•9m ago•0 comments

Host Your First Profitable Meetup or Mini-Conference

https://outlier-media-co.ever795522.chatgpt.site/ebook/
1•EverGonzalez76•11m ago•0 comments

Tell HN: Thanks for All the Fish

2•neilv•11m ago•0 comments

It may soon be possible to create "mirror life"

https://www.economist.com/science-and-technology/2026/09/30/it-may-soon-be-possible-to-create-mir...
1•vinni2•12m ago•0 comments

Decoupled DiLoCo for Resilient Distributed Pre-Training

https://arxiv.org/abs/2604.21428
1•lawrenceyan•15m ago•0 comments

Invisible XML (2025)

https://www.xml.com/articles/2025/12/02/invisible-xml-update/
4•devonnull•15m ago•0 comments

It's the Kernel's Fault! Custom Page Fault Handling With bpf_fault

https://dl.acm.org/doi/10.1145/3830418.3843896
1•matt_d•15m ago•0 comments

CM AI Docking Port: teaching AI agents to knock on the right door

https://apartmamatevz.si/journal/posts/2026-09-30-cm-ai-docking-port-teaching-ai-agents-to-knock-...
1•Cmfree•15m ago•0 comments

Show HN: Made a digital wall for AI Agents to "tag"

https://www.tomasmed.dev/wall
1•tomasmed•17m ago•1 comments

The Router Economy

https://www.lukascampos.com/blog/router-economy
1•lukaesch•17m ago•0 comments

Show HN: Aartool, Audit a Linux host and see which attack chains are complete

https://github.com/cyberaar/aartool
1•bantou96•18m ago•0 comments

USPS to Put Cameras in Trucks That Scan Roads for 'Community Safety'

https://www.404media.co/usps-to-put-cameras-in-trucks-that-scan-roads-for-community-safety/
3•dualvariable•19m ago•1 comments

Agentic GPU Programming for MLSys

https://mlc.ai/agentic-gpu-programming-for-mlsys/index.html
1•matt_d•19m ago•0 comments

Gemini 4 Argon (High): Intelligence, Performance and Price Analysis

https://artificialanalysis.ai/models/gemini-4-argon
4•theanonymousone•23m ago•1 comments

Purlin: Separating Orchestration from the Datapath of Collectives

https://arxiv.org/abs/2609.36954
2•matt_d•24m ago•0 comments

Show HN: Preserve.Chat – Turn WhatsApp chats into sharable links

https://preserve.chat/
1•AsDivyansh•24m ago•0 comments

Gemini Skills Will Replace Gems; Gems Being Discontinued

https://workspaceupdates.googleblog.com/2026/09/skills-gemini-app-workspace.html
1•xd1936•25m ago•0 comments

Anthropic's IPO Prospectus Is a Fucking Doozy

https://daringfireball.net/linked/2026/09/30/reuters-anthropic-ipo-prospectus
10•danaris•29m ago•2 comments

Branch Target Reuse, BTR: New Spectre V2 Attack Targeting JIT Compilers

https://www.phoronix.com/news/Branch-Target-Reuse-BTR
3•porridgeraisin•32m ago•0 comments

More screen time is linked to poorer child development, study shows

https://www.cnn.com/2026/09/30/health/children-screen-time-study-scli-intl-wellness
3•smoyer•32m ago•0 comments

Vulnerability disclosures double to 10k per month as AI fuels exploitation

https://therecord.media/google-vulnerabilities-cyberattacks-ai
1•speckx•36m ago•0 comments

What is happening in Kyiv. A drone strike near my University [video]

https://www.youtube.com/watch?v=HmSHgjNYj7w
3•consumer451•36m ago•0 comments

Aurora PostgreSQL now supports querying of Apache Iceberg and Parquet data

https://aws.amazon.com/about-aws/whats-new/2026/09/aurora-postgresql-query-apache-iceberg-and-par...
6•daigoba66•36m ago•0 comments