frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Native HTML and CSS Features That Replaced JavaScript

https://ronaldsvilcins.com/2026/08/30/native-html-and-css-features-that-replaced-javascript/
1•eustoria•1m ago•0 comments

NASA Spaceflight Forums

https://pace.ping.de/oneill/site/
1•eustoria•2m ago•0 comments

Playgrnd – tiny tools for making weird, beautiful things

https://www.playgrnd.tools/
2•eustoria•2m ago•0 comments

The Little iPod That Could

https://blog.mattbearman.com/the-little-ipod-that-could/
2•MattBearman•4m ago•0 comments

We tried to send 500M+ notifs/mo on a $25 setup; novu costs $500K, knock $2.5M

https://notifkit.dev/articles/notifications-on-a-25-dollar-server
2•coo1estguy•5m ago•0 comments

Why Just Passwords?

https://pketh.org/why-just-passwords.html
2•ggoo•6m ago•0 comments

Self-hosting an AI agent environment with OpenCode and shared memory

https://smalldata.tech/blog/2026/10/11/self-hosting-an-ai-agent-environment-with-opencode-and-sha...
1•wheresvic4•8m ago•0 comments

We solved SQLite's single-writer limitation

https://marcobambini.substack.com/p/we-solved-sqlites-single-writer-limitation
1•marcobambini•8m ago•0 comments

Show HN: Notifications for Lit Web Components

https://github.com/brysonbw/lit-toaster
1•Brysonbw•9m ago•0 comments

Show HN: OpenCode server and TUI in a browser tab (Chrome desktop)

https://kkrausse.github.io/browser-agent-toolkit/
1•kkrausse•13m ago•0 comments

Show HN: Atlas Runa – E2E AI-enhanced language learning

https://atlasruna.com/
1•eamost•13m ago•0 comments

Tokyo Underground Club Turns Its Dancefloor into a "Reading Rave"

https://edm.com/events/tokyo-underground-club-reading-rave/
1•karakoram•14m ago•0 comments

VigilOSS – Harness for long running code audit and web pentests

https://www.reddit.com/r/redteamsec/s/SWrAgB6GcW
1•lmartineng•14m ago•0 comments

How Users Read on the Web (1997)

https://www.nngroup.com/articles/how-users-read-on-the-web/
1•petecooper•14m ago•0 comments

We Need a "Verified Email" Standard

https://iamvishnu.com/posts/verified-email-standard
1•vishnuharidas•14m ago•1 comments

Show HN: OpenClear – Self-hosted check and ACH fraud screening for small banks

https://github.com/chaffed/OpenClear
1•villson•20m ago•0 comments

Versioned Filesystem for Disposable Sandboxes

https://www.shayon.dev/post/2026/283/versioned-filesystem-for-disposable-sandboxes/
2•shayonj•22m ago•0 comments

Addicts, vicars, madmen, murderers: Oxford English Dictionary's unlikely writers

https://www.theguardian.com/books/2023/sep/13/sarah-ogilvie-oxford-english-dictionary
1•theanonymousone•23m ago•0 comments

Facebook Marketplace Reaper Automate Marketplace Finder

https://github.com/poboisvert/fb-marketplace-reaper
1•pob944•23m ago•0 comments

Vibecoded 3D Game Running on Veda OS

1•vahmoh25•23m ago•0 comments

Eritrea invaded Ethiopia, conflict getting worse

https://www.cfr.org/global-conflict-tracker/conflict/conflict-ethiopia
1•AndrewKemendo•28m ago•1 comments

The Corporate Happiness Treadmill and the Case for Doing Less

https://0xff.nu/corp-burnout/
3•hxii•28m ago•0 comments

Bothering to understand

https://www.autodidacts.io/bothering-to-understand/
2•Curiositry•29m ago•0 comments

Ledger Nano X: the spy implant

https://www.tibane.net/research/ledger-nano-x-implant
2•MC995•30m ago•0 comments

John Sculley: Apple is suing Steve Jobs (September 23, 1985)

https://twitter.com/TechEmails/status/2109308345815650432
1•theanonymousone•30m ago•0 comments

How to Build Wealth as a Career Person

https://asheradeniyi.com/2026/04/10/how-to-build-wealth-as-a-career-person/
2•doppp•30m ago•0 comments

Birds take off, then some academic lectures birds how to fly and takes credit

https://twitter.com/nntaleb/status/2109265194589528431
2•caaqil•30m ago•0 comments

I cut my agent token usage in half

https://github.com/IOServicesLabs/indexio
3•iohotspot•30m ago•1 comments

Building Products People Are Glad They Used

https://www.tyleo.com/blog/building-products-people-are-glad-they-used
2•tyleo•33m ago•0 comments

Show HN: Write once. Explain well. Publish on the web and on paper

https://github.com/insanai/guidedog
1•vikrantrathore•34m ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.