frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

The just-say-no engineer was a ZIRP phenomenon

https://www.seangoedecke.com/the-just-say-no-engineer-was-a-zirp-phenomenon/
1•theanonymousone•5m ago•0 comments

Governments are ruining the internet to protect kids

https://www.neowin.net/editorials/governments-are-ruining-the-internet-to-protect-kids-but-there-...
1•bundie•5m ago•0 comments

Mounting Git commits as folders with NFS

https://jvns.ca/blog/2023/12/04/mounting-git-commits-as-folders-with-nfs/
1•pvtmert•5m ago•1 comments

Korean bill seeks strict watermark mandate on AI-generated content

https://www.koreatimes.co.kr/business/tech-science/20260517/korean-bill-seeks-strict-watermark-ma...
1•01-_-•8m ago•0 comments

A new EDIT tool for LLM agents

https://antirez.com/news/166
2•surprisetalk•8m ago•0 comments

Darwin Family: MRI-Trust-Weighted Evolutionary Merging

https://arxiv.org/abs/2605.14386
1•cheuv•8m ago•0 comments

Brain "Bypass" Technology Could Transform Treatment for Neurological Disorders

https://scitechdaily.com/new-brain-bypass-technology-could-transform-treatment-for-neurological-d...
1•01-_-•9m ago•0 comments

My domain got abused on GitHub Pages

https://meertens.dev/blog/github-enables-domain-abuse/
1•rmeertens•9m ago•0 comments

How We Hacked Our Way to Free 4.0s and Took Over a uWaterloo & UofT Grading Tool

https://xtra.sh/blog/markus/
1•xtra1•10m ago•0 comments

How to Select a Mobile OS

https://blog.gridranger.dev/mobile-oses-featuring-fairphone-5/
1•vinhnx•12m ago•0 comments

Why Elon Musk lost his suit against OpenAI

https://www.technologyreview.com/2026/05/18/1137488/elon-musk-suit-openai-verdict/
1•joozio•12m ago•0 comments

Topological Relativity Theory: A Quantum Gauge Field Framework

https://zenodo.org/records/20262720
1•kisnorbert•14m ago•0 comments

Meta lays out details of May 20 restructuring in internal document

https://www.reuters.com/world/meta-lays-out-plans-may-20-layoffs-restructuring-internal-document-...
1•theonionspeaks•15m ago•0 comments

My 40-liter backpack travel guide

https://vitalik.eth.limo/general/2022/06/20/backpack.html
1•bushwart•19m ago•1 comments

Kerf (Kerf1)

https://github.com/kevinlawler/kerf1
1•tosh•19m ago•0 comments

MXToolbox Alternative

https://dmarcguard.io/blog/mxtoolbox-alternative/
1•meysamazad•20m ago•0 comments

Thoughts on People and Blogs

https://afranca.com.br/thoughts-on-people-and-blogs/
1•meysamazad•21m ago•0 comments

Computers and Upgrades

https://www.unsungnovelty.org/posts/05/2026/computers-and-upgrades/
1•meysamazad•22m ago•0 comments

Why math and biology make organizational perfection impossible

https://ksaweryskowron.substack.com/p/managing-is-not-about-reaching-perfection
1•ksaweryskowron•22m ago•0 comments

NYSE: Daily TAQ Client Specifications [pdf]

https://www.nyse.com/publicdocs/nyse/data/Daily_TAQ_Client_Spec_v4.3.pdf
1•tosh•23m ago•0 comments

Build a Searchable Catalog with Filters, Facets, and Semantic Search

https://medium.com/@s_nikolaev/build-a-searchable-catalog-with-filters-facets-and-semantic-search...
1•snikolaev•23m ago•0 comments

2026 – agents break containment, what's next?

https://www.bradwmorris.com/posts/free-the-claw-agents-break-containment
1•bradwmorris•25m ago•0 comments

Gelatine Sculpt Weight Loss Claims Evaluated: The Truth Behind the Gelatin Trick

https://finance.yahoo.com/sectors/healthcare/articles/gelatine-sculpt-exploding-2026-viral-142500...
1•tarjzapu•27m ago•0 comments

How to Save Bloated MCP with Code Mode

https://zenstack.dev/blog/mcp-code-mode
2•jsgood•29m ago•0 comments

Pythagorean Addition

https://entropicthoughts.com/pythagorean-addition
3•Tomte•31m ago•0 comments

The programmer whose code underpins the Interne

https://www.scientificamerican.com/article/the-programmer-whose-code-underpins-the-internet/
2•tzury•32m ago•0 comments

Linus Torvalds on the continued flood of AI bug reports

https://lkml.org/lkml/2026/5/17/896
2•tzury•34m ago•0 comments

Simulating Infinity in Conway's Game of Life with Modern C++

https://ryanjk5.github.io/posts/GOLDE/
1•signa11•36m ago•0 comments

AI Cold War Is a Marketing Gimmick

https://sinodatacrit.substack.com/p/ai-cold-war-is-a-marketing-gimmick
1•dlcmh•36m ago•0 comments

Apple vs. EU Commission: DMA second round

https://fsfe.org/news/2026/news-20260519-01.en.html
3•softwarefreedom•41m ago•2 comments