frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: Claude Code Arcade

https://github.com/jystervinou/claude-code-arcade
1•jystervinou•1m ago•0 comments

Show HN: I made a minimalist digital zine powered by 5 random emoji prompts

https://moon-zine.net/
1•riedhes•2m ago•0 comments

Show HN: Sheet-Based Infrastructure, Sheeternetes and Sheet-Native Foundation

https://sncfoundation.github.io/landscape.html
1•tym83•2m ago•0 comments

LaSuite.coop

https://lasuite.coop/
1•ngrislain•4m ago•0 comments

LiveSplit

http://livesplit.org/
1•skibz•7m ago•0 comments

Elon Musk did well for a penniless immigrant

https://utopiayouarestandinginit.com/2026/08/31/elon-musk-did-well-for-a-penniless-immigrant/
1•speckx•7m ago•0 comments

old.reddit.com Now Requires Log-In

https://www.old.reddit.com
3•ed95•9m ago•0 comments

Nvidia-Labs Object Oriented Agents

https://github.com/NVIDIA-NeMo/labs-OO-Agents
1•wslh•10m ago•0 comments

Vexatious Litigants

https://www.gov.uk/guidance/vexatious-litigants
1•robin_reala•10m ago•0 comments

Show HN: Transform text and images into cinematic AI videos

https://h3max.app/
1•wowinter15•11m ago•0 comments

The brain struggles to make new neurons in people with depression

https://www.nature.com/articles/d41586-026-02661-8
2•bookofjoe•13m ago•1 comments

Why Garfield Phones Are Washing Up on a French Beach Since the '80s

https://www.thisiscolossal.com/2026/08/silly-little-plastic-cat-short-film/
1•gmays•14m ago•0 comments

Top Remote Work Trends in Germany in 2026

https://www.foxapply.com/blog/en/remote-work-trends-germany-2026
1•josanjohnata•14m ago•0 comments

The law won't save us from Meta's 'pervert glasses' The only solution is mockery

https://www.theguardian.com/commentisfree/2026/aug/31/law-meta-pervert-glasses-mockery
5•6LLvveMx2koXfwn•15m ago•0 comments

Show HN: Room Treatment

https://roomtreatment.diy/landing
3•gregojaca•15m ago•0 comments

Dropbox Got Hacked

https://twitter.com/yonilevy/status/2094521566826541248
4•yonilevy•15m ago•0 comments

One False Alert and Zero False Autonomous Actions in over 15,000 Pod-Hours

https://pandocore.io/blog/clean-run-soak-results
1•eaferstl•17m ago•0 comments

The river of Apple's interface guidelines

https://hig.josefrichter.design/
2•josefrichter•17m ago•0 comments

Show HN: Keel - A conductor, not an agent loop

https://daneb.github.io/keel/
1•danebalia•18m ago•0 comments

Show HN: Doom Compiled into an LLM

https://github.com/physicsrob/torchwright_doom/
1•physicsrob•19m ago•0 comments

Dropbox Data Breach

4•hmate9•21m ago•1 comments

Pebble Index 01 sold as open-source, but proprietary

https://github.com/coredevices/mobileapp/issues/333
1•okso•21m ago•1 comments

Show HN: Terminal-browser – A real browser inside the terminal

https://github.com/zenbu-labs/terminal-browser
3•robpruzan•21m ago•0 comments

Show HN: Super CLI MARIO – a Mario clone for your terminal in zero-dependency Go

https://blog.daviey.com
1•Daviey•23m ago•1 comments

The Conglomerate Premium

https://hypersoren.xyz/posts/conglomerate-premium/
1•handfuloflight•25m ago•0 comments

South Korea opened bidding for a free, unlimited AI chatbot for all citizens

https://thenextweb.com/news/south-korea-free-ai-chatbot-all-citizens-domestic-models
4•quantisan•26m ago•0 comments

An offline code scanner with a Node.js network guard to block cloud leaks

https://simplebeacon.ai/
1•TJP88•26m ago•0 comments

Show HN: PopSQL and SeekWell were shutting down, so I built the replacement

https://saturnsql.com
3•infr88•26m ago•0 comments

RFM analysis: not all 64 R-F-M score combinations map to a segment

https://www.erathos.com/en/blog/rfm-analysis
1•gpaulbagetti•27m ago•0 comments

Pglogs

https://pglogs.dev/
1•handfuloflight•28m ago•0 comments