frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

TikTok is tracking you, even if you don't use the app

https://www.bbc.com/future/article/20260210-tiktok-is-tracking-you-even-if-you-dont-use-the-app-h...
1•tmoravec•1m ago•0 comments

Show HN: ChatProjects Open-source WordPress plugin for document RAG and chat

https://github.com/chatprojects-com/chatprojects
1•morog•1m ago•0 comments

Show HN: Baby Vault – A 100% offline, privacy-first PWA for new parents

https://babyvault.moshmage.com/
1•moshmage•3m ago•1 comments

AI liability as the anchor of the human role

https://okossa.com/the-era-of-ai-liability-is-the-anchor-of-the-human-role-c55a11015765
1•okwe•3m ago•0 comments

StoreMind AI for Shopify

1•StoreMindAI•4m ago•0 comments

Show HN: Attestia – Financial truth layer for Web3 (TS, 1176 tests, 97% cov)

https://github.com/mcp-tool-shop-org/Attestia
1•mikeyfrilot•5m ago•0 comments

Michael Edward Ash

https://en.wikipedia.org/wiki/Michael_Edward_Ash
1•ZeljkoS•5m ago•0 comments

Blazorise 2.0 released, 3 years in the making

https://blazorise.com/news/release-notes/200
1•stsrki•5m ago•0 comments

Show HN: I built managed OpenClaw hosting with 60s provisioning in 6 days

https://clawhosters.com/blog/posts/how-i-built-60-second-vps-provisioning
2•yixn_io•8m ago•0 comments

The Shape of Time

https://aeon.co/essays/when-we-turned-time-into-a-line-we-reimagined-past-and-future
1•bryanrasmussen•10m ago•0 comments

The Architecture of a "Wrapper" Fraud: YwinCap

1•sunshaine•11m ago•0 comments

Math and Me

http://togelius.blogspot.com/2026/02/math-and-me.html
1•pretext•12m ago•0 comments

Stripe Dashboard is burning 10%+ CPU in Safari

https://twitter.com/__tosh/status/2021530350208405863
1•tosh•12m ago•0 comments

GLM 5 is pony-alpha

https://openrouter.ai/openrouter/pony-alpha
1•denysvitali•13m ago•1 comments

Startups with the Most Technical Debt Had the Best Funding Outcomes

https://bytevagabond.com/post/technical-debt-startup-funding
1•maxperience•15m ago•0 comments

Are AI SQL Yet?

https://www.viblo.se/posts/_are-ai-sql-yet/
1•viblo•15m ago•0 comments

FAA closes airspace around El Paso, Texas, for 10 days, grounding all flights

https://apnews.com/article/faa-el-paso-texas-air-space-closed-1f774bdfd46f5986ff0e7003df709caa
10•EwanG•16m ago•1 comments

The Missing GitHub Status Page

https://mrshu.github.io/github-statuses/
1•usrme•18m ago•0 comments

Alphabet selling rare 100 year bonds to help fund AI investment

https://arstechnica.com/gadgets/2026/02/alphabet-selling-very-rare-100-year-bunds-to-help-fund-ai...
1•holografix•20m ago•0 comments

AI will build your roadmap in ten seconds

https://orchidfiles.com/ai-will-build-your-roadmap-in-ten-seconds/
1•theorchid•23m ago•0 comments

CSRF Is Dead, Long Live Request Intent

https://erdem.work/csrf-is-dead-long-live-request-intent-the-anatomy-of-a-cryptographic-primitive
1•laphilosophia•23m ago•1 comments

Show HN: I built a tool for lazy founders – it's called BunnyDesk

https://bunnydesk.ai
2•jacobsyc•23m ago•0 comments

Show HN: Claudit – Claude Code Conversations as Git Notes, Automatically

https://github.com/re-cinq/claudit
2•EngineerBetter•25m ago•0 comments

Computer Agent Feedback

https://aglit.ai/
1•alphabetnerd•26m ago•0 comments

Exposure Simulator

http://www.andersenimages.com/tutorials/exposure-simulator/
2•sneela•27m ago•0 comments

Tech workers are frustrated by their companies silence about ICE

https://www.theverge.com/ai-artificial-intelligence/876558/tech-workers-ice-resistance-google-mic...
3•october8140•27m ago•1 comments

Show HN: A Distribution Framework for founders who can build but can't sell

https://beyondfolder.com/distribution
1•raress96•30m ago•0 comments

Show HN: Create and Run PC Automations from Plain English with Automate AI Free

1•aleeexg•33m ago•0 comments

The cost of AI coding agents isn't from AI at all

https://www.coderabbit.ai/ja/blog/the-hidden-cost-of-ai-coding-agents-isnt-from-ai-at-all
1•alokDT•40m ago•0 comments

I Quit My Job at OpenAI

https://www.nytimes.com/2026/02/11/opinion/openai-ads-chatgpt.html
7•cainxinth•42m ago•1 comments