frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•12mo ago

Comments

kemotep•12mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Rspack 2.0: a 10x faster Webpack built in Rust

https://rspack.rs/blog/announcing-2-0
1•AbuAssar•1m ago•0 comments

Why I Still Reach for Lisp (& Scheme) Instead of Haskell

https://jointhefreeworld.org/blog/articles/lisps/why-i-still-reach-for-scheme-instead-of-haskell/...
1•jjba23•2m ago•0 comments

Product Thinking for Open Source Library Design

https://pckt.blog/b/krzysu/product-thinking-for-open-source-library-design-qzw69a9
3•krzysu•7m ago•0 comments

A free solution to the GitHub Actions supply chain crisis

https://developerwithacat.com/blog/202604/github-actions-supply-chain-commit/
1•pabs3•11m ago•0 comments

Mining magnate Andrew Forrest takes Meta 2 court over scam ads using his likenes

https://www.abc.net.au/news/2026-04-17/andrew-forrest-battles-meta-over-fake-ads/106574806
2•asdefghyk•12m ago•1 comments

The Wrong Black Box Problem

https://dekodiert.de/en/articles/das-falsche-black-box-problem
6•sdoering•13m ago•0 comments

The EC is turning Google Search into a privacy and national-security risk

https://blog.lukaszolejnik.com/the-european-commission-is-turning-google-search-into-a-privacy-an...
3•negura•15m ago•0 comments

Building a Basic Cache with SQLite

https://alexwlchan.net/2026/sqlite-cache/
5•ingve•15m ago•0 comments

Why C++ Wins in Finance(2026)

https://www.youtube.com/watch?v=InLxLEqg_fs
5•theawesomekhan•16m ago•0 comments

Ubuntu silicon-optimized inference snaps for AI

https://canonical.com/blog/canonical-releases-inference-snaps
2•jmngomes•17m ago•0 comments

Show HN: LLM-assisted reconstruction of partially decompiled Minecraft 26.1.2

https://github.com/stevefan1999-personal/demcstify
7•stevefan1999•17m ago•0 comments

Ask HN: How are you stopping supply chain attacks via compromised dev keys?

5•CountVonGuetzli•20m ago•0 comments

The world is rejecting science and truth, here are 5 ways to fight back

https://www.theguardian.com/commentisfree/2026/apr/28/world-rejecting-science-truth-five-ways-fig...
6•JeanKage•22m ago•0 comments

Native vs. Cross Compilation: A Love Story,a War Story and a Debugging Nightmare

http://carminatialessandro.blogspot.com/2026/04/native-vs-cross-compilation-love-story.html
5•throw324du•24m ago•0 comments

Back Up and Running

https://blog.tindie.com/2026/04/back-up-and-running/
9•zimpenfish•26m ago•1 comments

Vanishing Culture: A New Book on the Loss of Our Digital Memory

https://blog.archive.org/2026/04/23/introducing-vanishing-culture-a-new-book-on-the-loss-of-our-d...
5•robtherobber•27m ago•0 comments

The Great Oxidation Event: How Cyanobacteria Changed Life

https://asm.org/articles/2022/february/the-great-oxidation-event-how-cyanobacteria-change
7•thunderbong•27m ago•0 comments

How to distribute skills to your engineers

https://newsletter.port.io/p/how-to-build-a-skills-library-for-your-engineering-team
7•krakenwake•28m ago•0 comments

Predictive pursuit emerges in high-dimensional recurrent neural networks

https://www.biorxiv.org/content/10.64898/2026.04.23.720457v1
4•paraschopra•28m ago•0 comments

Beijing Auto Show: more EV models in each of 17 halls than in the US

https://electrek.co/2026/04/26/beijing-auto-show-2026-insane-glimpse-future-auto-industry/
3•Geekette•31m ago•0 comments

Rusternetes : A ground-up reimplementation of Kubernetes in Rust

https://github.com/calfonso/rusternetes
11•mariuz•32m ago•1 comments

Our first paying user found us from China in 4 days – zero marketing

https://mfkvault.com
6•faiyaz2139•36m ago•0 comments

Ask HN: Should it be acceptable that Excel needs to update 2-3 times/month?

4•simonebrunozzi•37m ago•0 comments

Big AI Cluster Little Power the 8x Nvidia GB10 Cluster – ServeTheHome

https://www.servethehome.com/big-cluster-little-power-the-8x-nvidia-gb10-cluster-marvell-cisco-ub...
8•rbanffy•37m ago•0 comments

Stevens Online World of Blade Runner (2001)

http://www.users.globalnet.co.uk/~stvens/BLADE.htm
4•exvi•37m ago•0 comments

The players who lost big money on Peter Molyneux's failed Legacy

https://arstechnica.com/gaming/2026/04/how-legacy-became-a-costly-crypto-bust-for-players-and-a-b...
8•rbanffy•39m ago•0 comments

Curiosity Rover Finds New Organic Molecules on Mars

https://www.universetoday.com/articles/msl-curiosity-found-new-organic-chemicals-on-mars-proof-th...
10•rbanffy•40m ago•0 comments

Tooling Up Hermes Agent

https://nedkarlovich.com/writing/tooling-up-hermes-agent
6•birdwhistler•40m ago•0 comments

openclaw ggsql

https://clawhub.ai/fanzhidongyzby/openclaw-ggsql
7•fanzhidongyzby•43m ago•0 comments

Carrot Disclosure

https://dustri.org/b/carrot-disclosure.html
6•pabs3•43m ago•0 comments