frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•10mo ago

Comments

kemotep•10mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

European Central Bank: AI may be creating instead of destroying jobs for now

https://www.reuters.com/business/ai-may-be-creating-instead-destroying-jobs-now-ecb-blog-argues-2...
1•giuliomagnifico•39s ago•0 comments

Marc Benioff Praises Grok

https://twitter.com/cb_doge/status/2028936688689352818
1•sourcegrift•2m ago•0 comments

Show HN: Glyph, a local-first Markdown notes app for macOS built with Rust

https://glyphformac.com/
1•skarat•4m ago•0 comments

A Shared Kernel Is a Shared Trust Domain

https://cdelmonte.dev/posts/shared-kernel-shared-trust-domain/
1•cdelmonte•7m ago•0 comments

2025 State of Rust Survey Results

https://blog.rust-lang.org/2026/03/02/2025-State-Of-Rust-Survey-results/
1•pjmlp•8m ago•0 comments

Man Cereal

https://joshcollinsworth.com/blog/man-cereal
1•jannesan•9m ago•0 comments

IANA tz (and POSIX) cannot add British Columbia's new Pacific Time (PT) timezone

https://github.com/eggert/tz/commit/8b46071fd85a7a9434d63894bac64d30362cc16d
1•kelseydh•9m ago•0 comments

Show HN: Most Based

https://www.mostbased.space/
1•aloscorisreal•9m ago•0 comments

Show HN: Read it later" links only (iOs app)

https://apps.apple.com/gb/app/space4links/id6758895070
1•skyfantom•10m ago•0 comments

Show HN: We build a Graph of public Skills

https://skillinsight.io
3•mapleeman•16m ago•2 comments

Show HN: Elm Social Route – Geofenced chat, event, and route

https://play.google.com/store/apps/details?id=com.hujan2labs.elmsocialroute&hl=en_US
1•red26•17m ago•0 comments

Lockbox: Constrain Your Bots to Set Them Free

https://www.chrismdp.com/lockbox-constrain-your-bots-to-set-them-free/
1•refset•17m ago•0 comments

Startup Failure Often Starts with a Bad Idea. This Helps Prevent That

1•doxd•19m ago•0 comments

Moss is a pixel canvas where every brush is a tiny program

https://www.moss.town/
1•smusamashah•19m ago•0 comments

UK Royal Air Force flight tracker

https://raf.watch/
3•ltrg•22m ago•0 comments

Incrmd: Incremental AI coding by editing PROJECT.md

https://github.com/b4rtaz/incrmd
1•b4rtaz__•23m ago•0 comments

ClawOffice – Real Office for Your Open Claw Agents

https://office.clawoneclick.com/en
2•tarasshyn•24m ago•1 comments

Markly – Watermark images from Claude via MCP (free, no API key needed)

https://github.com/Whitemarmot/markly-mcp-server
1•whitemarmot•28m ago•1 comments

Show HN: CastLocal – Stream any local video to Chromecast from your terminal

https://github.com/YuriKovalov22/cast-control
2•YuriiKovalov•29m ago•1 comments

Multi-agent Claude Code setup – 3 roles, Markdown coordination, Docker

https://github.com/yury-egorenkov/claude-code-docker
1•yego•34m ago•3 comments

InstantPhoto – browser photo editor, no account, no ads, no watermarks

https://www.instantphoto.studio/
2•popik•34m ago•0 comments

Climbing Mechanics in Games [video]

https://www.youtube.com/watch?v=-d4YHTpfi0g
1•GanteRooibos•35m ago•1 comments

Hiroo Onoda, the Soldier Who Kept Fighting World War II Until 1974

https://allthatsinteresting.com/hiroo-onoda
2•thunderbong•39m ago•0 comments

Smalltalk's Browser: Unbeatable, yet Not Enough

https://blog.lorenzano.eu/smalltalks-browser-unbeatable-yet-not-enough/
4•xkriva11•40m ago•0 comments

Show HN: An AI-native workspace for founders with zero-knowledge encryption

https://twitter.com/thealsufii/status/2029133477904306339
3•alsufinow•41m ago•1 comments

Robot LCD display face with a 3D printed Lego helmet

https://blog.adafruit.com/2026/03/03/robot-lcd-display-face-with-a-3d-printed-lego-helmet/
1•tzury•43m ago•0 comments

The Best Liar

https://medium.com/luminasticity/the-best-liar-4f036f78b601
1•bryanrasmussen•44m ago•1 comments

A survey of write protect notches on floppy disks and other media

https://devblogs.microsoft.com/oldnewthing/20260303-00/?p=112104
2•ingve•48m ago•0 comments

OpenWrt 25.12.0 – Stable Release

https://openwrt.org/releases/25.12/notes-25.12.0
2•giuliomagnifico•49m ago•0 comments

Attorneys get majority of payouts from handicap-accessible website lawsuits

https://www.wsbtv.com/news/local/attorneys-getting-most-money-thousands-lawsuits-handicap-accessi...
3•gosub100•51m ago•2 comments