frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•7mo ago

Comments

kemotep•7mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: Python Package for fine-tuning LLMs without writing code

https://github.com/shrut2702/upasak
1•shroot2702•47s ago•0 comments

Mac Cleaner CLI: Free and Open Source Mac Cleanup Tool

https://github.com/guhcostan/mac-cleaner-cli
1•todsacerdoti•3m ago•0 comments

Users Struggle with the Instagram Repost Button

https://www.nytimes.com/2025/12/06/technology/instagram-repost-button-accidental.html
1•lxm•3m ago•0 comments

Stack Overflow AI Assist

https://stackoverflow.com/ai-assist
1•theanonymousone•3m ago•0 comments

Berkshire Hathaway Announces Leadership Appointments [pdf]

https://berkshirehathaway.com/news/dec0825.pdf
1•kamaraju•4m ago•0 comments

I'm so sorry, but you don't get to know the truth right now (2023)

https://www.sltrib.com/opinion/commentary/2023/10/10/adam-mastroianni-im-so-sorry-you/
1•indigodaddy•4m ago•0 comments

Backdoors to Typical Case Complexity

https://danglingpointers.substack.com/p/backdoors-to-typical-case-complexity
1•blakepelton•4m ago•0 comments

Paramount bids $18B more for Warner Bros than Netflix

https://www.reuters.com/legal/transactional/insant-view-paramount-makes-1084-billion-hostile-bid-...
1•defly•4m ago•0 comments

TIL cognitive snapshots can be permanent seeds

https://doi.org/10.13140/RG.2.2.29430.05445
1•GeldiBey•5m ago•0 comments

Magnitude 7.2 quake strikes off Japan's northern coast, triggers a tsunami alert

https://apnews.com/article/japan-quake-hokkaido-tusnami-alert-13b3149989918a8f860903ec48b1af92
2•1f97•6m ago•0 comments

AI Recommendations for 2026 – Agents, Infra, Models and More

https://brettdidonato.substack.com/p/6-ai-recommendations-for-2026
1•bsdpython•8m ago•0 comments

AI Slop PRs as an Attack

https://tylur.blog/harmful-prs/
2•franky47•9m ago•0 comments

"Yeah." –Elon Musk

https://nickbostrom.com/deep-utopia/
1•danielfalbo•9m ago•0 comments

What the Cyber Resilience Act (CRA) Means for Hardware Manufactures

https://thymis.io/en/blog/cra-hardware-developers
1•Margmas•10m ago•0 comments

7.6 earthquake off the coast of Japan

https://www.data.jma.go.jp/multi/quake/quake_detail.html?eventID=20251208232600&lang=en
3•LadyCailin•10m ago•0 comments

Pyversity with Thomas van Dongen

1•CShorten•10m ago•0 comments

Lawyers are uniquely well-placed to resist AI job automation

https://boydkane.com/essays/2025nov#lawyers-are-uniquely-well-placed-to-resist-ai-job-automation-...
2•beyarkay•12m ago•2 comments

Computers Store Decimal Numbers

https://sergiorodriguezfreire.substack.com/p/how-computers-store-decimal-numbers
1•birdculture•13m ago•0 comments

Nova Programming Language

https://nova-lang.net
2•surprisetalk•13m ago•0 comments

Software Never Fails

https://entropicthoughts.com/software-never-fails
1•surprisetalk•13m ago•0 comments

Making the Solution Transparent

https://buttondown.com/dorian/archive/making-the-solution-transparent/
1•surprisetalk•13m ago•0 comments

Branch, Test, Deploy: A Git-Inspired Approach for Data

https://motherduck.com/blog/git-for-data-part-1/
1•surprisetalk•13m ago•0 comments

We Solved Scale, but Lost Cohesion

https://johnocens.com/soothfare/WeSolvedScalebutLostCohesion
1•wonderbar•14m ago•1 comments

Paramount Attempts Hostile Offer for Warner Bros

https://www.hollywoodreporter.com/business/business-news/paramount-launches-hostile-bid-for-warne...
2•throw0101d•15m ago•0 comments

Uber starts selling ride/eats data to marketers

https://www.businessinsider.com/uber-ads-launches-intelligence-insights-trips-takeout-data-market...
8•sethops1•16m ago•1 comments

The Accounting Uproar over How Fast an AI Chip Depreciates

https://www.wsj.com/finance/investing/the-accounting-uproar-over-how-fast-an-ai-chip-depreciates-...
1•JumpCrisscross•17m ago•0 comments

Show HN: CocoIndex – Open-Source Data Engine for Dynamic Context Engineering

https://github.com/cocoindex-io/cocoindex
1•georgehe9•17m ago•0 comments

Gyromorphs: A new class of functional disordered materials

https://arxiv.org/abs/2410.09023
1•PaulHoule•18m ago•0 comments

How we built context management for tab completion

https://docs.getpochi.com/developer-updates/context-management-in-your-editor/
4•wsxiaoys•18m ago•1 comments

Microsoft is quietly walking back its diversity efforts

https://www.theverge.com/tech/838079/microsoft-diversity-and-inclusion-changes-notepad
20•mohi-kalantari•19m ago•9 comments