frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: We open-sourced MusePro, a Metal-based realtime AI drawing app for iOS

https://github.com/StyleOf/MusePro
1•okaris•4m ago•0 comments

Launching Interop 2026

https://hacks.mozilla.org/2026/02/launching-interop-2026/
1•linolevan•5m ago•1 comments

Show HN: Create a clean tree graph of your projects with my App on iOS

https://apps.apple.com/us/app/motive-project-visualiser/id6754777255
1•Seth_k•7m ago•0 comments

Seven Billion Reasons for Facebook to Abandon Its Face Recognition Plans

https://www.eff.org/deeplinks/2026/02/seven-billion-reasons-facebook-abandon-its-face-recognition...
2•hn_acker•8m ago•0 comments

Andreessen vs. Thiel

https://web.archive.org/web/20200318115004/https://allenleein.github.io/2019/06/12/games2.html
1•eamag•11m ago•0 comments

Show HN: Infoseclist.com – Compare 90 cybersecurity tools ranked by practition

https://infoseclist.com/
1•aleks5678•12m ago•0 comments

Show HN: Clonar – A Node.js RAG pipeline with 8-stage multihop reasoning

https://github.com/clonar714-jpg/clonar
1•sowmith-tsrc•12m ago•1 comments

Grub 2.0

https://grubcrawler.dev
2•kordlessagain•12m ago•0 comments

Cmux: Tmux for Claude Code

https://github.com/craigsc/cmux
2•Soupy•14m ago•1 comments

Trump FTC wants Apple News to promote more Fox News and Breitbart stories

https://arstechnica.com/tech-policy/2026/02/trump-ftc-denies-being-speech-police-but-says-apple-n...
4•pseudalopex•14m ago•0 comments

Posteo and Mailbox.org: Many authorities do not create encrypted requests

https://www.heise.de/en/news/Posteo-and-Mailbox-org-Many-authorities-do-not-create-encrypted-requ...
2•doener•14m ago•0 comments

Google Might Think Your Website Is Down

https://codeinput.com/blog/google-seo
2•janpio•16m ago•0 comments

Show HN: TrustVector – Trust evaluations for AI models, agents, & MCP

https://github.com/guard0-ai/TrustVector
1•hckdisc•17m ago•1 comments

An AI Agent Published a Hit Piece on Me [pdf]

https://img.sauf.ca/pictures/2026-02-12/88fce2f8bbe49f40d83dec69800a2aa9.pdf
1•ColinWright•17m ago•2 comments

4K Restoration: 1984 Super Bowl Apple Macintosh Ad by Ridley Scott [video]

https://www.youtube.com/watch?v=ErwS24cBZPc
1•ipnon•18m ago•0 comments

Show HN: First Embeddable Web Agent

https://www.rtrvr.ai/blog/10-billion-proof-point-every-website-needs-ai-agent
2•arjunchint•19m ago•0 comments

Major 'vibe-coding' platform Orchids is easily hacked, researcher finds

https://www.bbc.com/news/articles/cy4wnw04e8wo
2•ColinWright•19m ago•0 comments

Resist and Unsubscribe

https://www.resistandunsubscribe.com
3•anielsen•22m ago•1 comments

Auto CPU freq rust port

https://github.com/Zamanhuseyinli/auto-cpufreq-rust
1•goychay23•22m ago•1 comments

Remote Labor Index: Measuring AI Automation of Remote Work

https://arxiv.org/abs/2510.26787
1•Leynos•23m ago•0 comments

AI bot crabby-rathbun is still polluting open source

https://www.nickolinger.com/blog/2026-02-13-ai-bot-crabby-rathbun-is-still-going/
1•olingern•23m ago•2 comments

How often do full-body MRIs find cancer?

https://www.usatoday.com/story/life/health-wellness/2026/02/11/full-body-mris-cancer-aneurysm/883...
2•brandonb•24m ago•0 comments

Show HN: Reddit Online User Tracker – Find the Best Time to Post on Reddit

https://spectreseo.com/tools/best-time-to-post-on-reddit
1•warrenjday•24m ago•0 comments

Show HN: Rampart – Runtime firewall for Claude Code and AI agents in YOLO mode

https://github.com/peg/rampart
2•trevxr•25m ago•0 comments

Top Free Tools to Spice Up Your Valorant Stream (2026)

https://killervibe.app/blog/top-5-free-tools-valorant-stream
1•Jikouken•28m ago•0 comments

OpenAI has deleted the word 'safely' from its mission

https://theconversation.com/openai-has-deleted-the-word-safely-from-its-mission-and-its-new-struc...
108•DamnInteresting•29m ago•28 comments

Show HN: Darius – An AI router that selects the best model for each prompt

https://withdarius.com
3•mazenkurdi•30m ago•0 comments

GE-Proton10-30

https://github.com/GloriousEggroll/proton-ge-custom/releases/tag/GE-Proton10-30
1•linux4dummies•34m ago•0 comments

Workledger – An offline first engineering notebook

https://about.workledger.org/
4•birdculture•34m ago•1 comments

I'm a Professional Chef in Antarctica

https://www.theguardian.com/lifeandstyle/2026/feb/13/experience-im-a-professional-chef-in-antarctica
3•bookofjoe•34m ago•0 comments