frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

How to Mirror from Sourcehut to GitHub

https://timharek.no/blog/mirror-sourcehut-to-github/
1•netule•3m ago•0 comments

Every dependency you add is a supply chain attack waiting to happen

https://benhoyt.com/writings/dependencies/
1•signa11•4m ago•0 comments

Rancho Gordo trademarks 'bean club,' tells others to stop using it

https://www.sfchronicle.com/food/article/rancho-gordo-bean-club-trademark-22071347.php
1•littlexsparkee•5m ago•0 comments

Axios Maintainer Confirms Social Engineering Attack Behind NPM Compromise

https://socket.dev/blog/axios-maintainer-confirms-social-engineering-behind-npm-compromise
1•feross•5m ago•0 comments

The FusionAuth Brainf* SDK

https://fusionauth.io/blog/april-fools-brainf
1•mooreds•6m ago•0 comments

Run a Local LLM, and discover why LLMs are unpredictable

https://newsletter.bphogan.com/archive/issue-51-run-a-local-llm-and-discover-why-llms/
1•mooreds•7m ago•0 comments

The open web isn't dying. We're killing it

https://ouvre-boite.com/the-open-web-isnt-dying-were-killing-it/
1•benwerd•8m ago•0 comments

Tesla March car registrations soar in key European markets

https://www.reuters.com/business/retail-consumer/tesla-french-car-registrations-triple-march-2026...
2•havaloc•11m ago•0 comments

How to Set Up Work and Personal Git Profiles

https://alex000kim.com/posts/2025-07-25-git-profiles/
1•teleforce•14m ago•0 comments

Slightly safer vibecoding by adopting old hacker habits

http://addxorrol.blogspot.com/2026/03/slightly-safer-vibecoding-by-adopting.html
1•transpute•20m ago•0 comments

Help on Posts

1•kvntrnz•24m ago•2 comments

Neoen to Build France's Largest Battery Amid Strained Power Grid

https://www.bloomberg.com/news/articles/2026-04-02/neoen-to-build-france-s-largest-battery-amid-s...
1•toomuchtodo•25m ago•1 comments

Artemis II commander enters tablet PIN on launch livestream

https://nypost.com/2026/04/02/us-news/artemis-ii-commander-enters-tablet-pin-on-launch-livestream...
1•wslh•27m ago•1 comments

Pinterest and Shopmy for AI-powered fashion shopping

https://faishion.ai
1•lucashe•31m ago•1 comments

All the Worst People Seem to Want to Be 'High Agency'

https://www.nytimes.com/2026/04/01/opinion/high-agency-silicon-valley.html
1•bonefishgrill•32m ago•0 comments

Pay to PrAI: Insert Coin to Try Again Podcast

https://www.macrovoices.com/1511-macrovoices-526-matt-barrie-pay-to-prai
1•mattbarrie•35m ago•1 comments

Making TinyLLM Go Brrrrr

https://vinayak.purelydysfunctional.com/blog/KVCache
2•murd3rbot•42m ago•0 comments

Paul Graham, Founder Y Combinator [video]

https://www.youtube.com/watch?v=2Q2uh1BlqKA
2•guiambros•44m ago•0 comments

Timeline of Microsoft's SmartNIC Tech (Azure Boost)

https://glennklockwood.com/garden/Azure-SmartNIC
2•WarOnPrivacy•45m ago•0 comments

Mars Terraforming Research Roadmap

https://arxiv.org/abs/2604.02242
2•edwinkite•46m ago•1 comments

5-Minute Crafts Has a Cybercrime Problem [video]

https://www.youtube.com/watch?v=ucRTW4rgrbU
1•exec01•47m ago•0 comments

Nvidia IGX Thor powers industrial, medical and robotics edge AI applications

https://developer.nvidia.com/blog/nvidia-igx-thor-powers-industrial-medical-and-robotics-edge-ai-...
1•teleforce•49m ago•0 comments

Show HN: Composer – AI architect / MCP for software architecture diagrams

https://www.usecomposer.com/
4•olivergrabner•49m ago•1 comments

The Catholic Priest Who Helped Write Anthropic's A.I. Ethics Code

https://observer.com/2026/03/the-catholic-priest-who-helped-write-anthropics-ai-ethics-code/
3•Geekette•51m ago•0 comments

I simulated a 19th-century utopian commune with AI agents

https://github.com/menggg22/utopia
3•menggg•53m ago•2 comments

Why OpenAI Decided to Buy 'TBPN,' Tech's Hottest News Show

https://www.wsj.com/tech/openai-technology-business-programming-network-b681ef6b
2•mudil•55m ago•0 comments

Referi – A trusted network for job referrals

https://www.referi.net
1•onlinemelvin•59m ago•0 comments

Show HN: LM Gate – Auth and access-control gateway for self-hosted LLM back ends

https://github.com/hkdb/lmgate
1•hkdb•1h ago•0 comments

Show HN: Claudebar, the missing interactive menu bar for Claude Code

https://github.com/LabLeaks/claudebar
1•didgeoridoo•1h ago•0 comments

Open-source runtime security toolkit for autonomous AI agents covering OWASP Top

https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-so...
1•mosiddi•1h ago•0 comments