frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Gnome 51 Could End Up Replacing System Tools with "Resources" App

https://www.phoronix.com/news/GNOME-51-Resources-Possible
1•rbanffy•2m ago•0 comments

Heat pumps and EVs can save EU households over €2,200 a year – report

https://www.euronews.com/2026/05/18/eu-households-could-save-more-than-2200-every-year-by-switchi...
2•rustoo•3m ago•0 comments

How China's Shadow AI API Market Works

https://www.vincentschmalbach.com/chinas-shadow-api-market/
1•vincent_s•3m ago•0 comments

I Updated Virtual Bookshelf

https://petargyurov.com/bookshelf/
1•petargyurov•3m ago•1 comments

Reviving old scanners with an in-browser Linux VM bridged to WebUSB over USB/IP

https://yes-we-scan.app/details
1•gmac•8m ago•0 comments

Dogme 25 – Vow of Chastity

https://dogma25.dk/
1•internet_points•10m ago•0 comments

FluidX3D Lands a Big Speed-Up for This OpenCL CFD Software

https://www.phoronix.com/news/FluidX3D-3.7-Released
1•rbanffy•11m ago•0 comments

Show HN: Libc-free, direct sys/kernel call language with weird concurrency

https://github.com/DO-SAY-GO/freelang
1•keepamovin•19m ago•1 comments

See You at Y10K: From Millennium Bugs to Quantum Midnight

https://space.gekko.de/from-y2k-to-q-day/
1•ekadagami•29m ago•0 comments

Show HN: Latlng – open-source geospatial object engine written in Rust

https://latlng.cloud/
1•tobilg•29m ago•0 comments

The Mysterious Crypto Judges Who Settle Polymarket Disputes

https://www.wsj.com/finance/polymarket-bet-disputes-fb1b8c6a
2•thm•31m ago•0 comments

The foundations of a provably secure operating system (PSOS) (1979) [pdf]

http://www.csl.sri.com/users/neumann/psos.pdf
11•rurban•35m ago•0 comments

A Node Based Brush Engine – PixiEditor 2.1

https://pixieditor.net/blog/2026/04/30/21-release/
1•axi_n•35m ago•0 comments

Zero Day Clock

https://zerodayclock.com/
1•jonbaer•37m ago•0 comments

Ebola outbreak with uncommon strain erupts in Congo and Uganda; 65 deaths

https://arstechnica.com/health/2026/05/ebola-outbreak-confirmed-in-congo-and-uganda-246-suspected...
2•rbanffy•38m ago•1 comments

An Empty Room: Each voice fades after 21 days

https://www.icried.today/
2•Teever•45m ago•0 comments

Protéger Mastodon contre les bots IA avec Anubis – Techno-Fil et faits divers

https://blogs.gayfr.social/barbapulpe/proteger-mastodon-contre-les-bots-ia-avec-anubis
1•rodrigo975•46m ago•0 comments

Where Are the Vibecoded Photoshops?

https://indiepixel.de/blog/posts/where-are-the-vibecoded-photoshops/
4•gizmo64k•47m ago•0 comments

Open and Free Security Books

https://nocomplexity.com/documents/securityarchitecture/securitylibrary/libraryintro.html#open-an...
1•runningmike•48m ago•1 comments

Safety Paradox: How RLHF Creates the AI Psychosis Problem It's Meant to Prevent

https://www.promptinjection.net/p/ai-psychosis-the-safety-paradox-how-rlhf-creates
1•JustMyNews•50m ago•2 comments

Are modern precision EDC knives worth the premium build cost?

https://www.paragon-knives.com/
1•bgzlsxaz•51m ago•0 comments

Don't Answer the First Question

https://lalitm.com/post/dont-answer-the-first-question/
1•lalitmaganti•54m ago•0 comments

Satellites May Be Driving a Concerning New Form of Atmospheric Pollution

https://thedebrief.org/satellites-may-be-driving-a-concerning-new-form-of-atmospheric-pollution-e...
1•JeanKage•55m ago•0 comments

Balance of Nature

https://en.wikipedia.org/wiki/Balance_of_nature
1•soupspaces•55m ago•0 comments

Fireside Chat with Bjarne Stroustrup at CTO Summit 2025 Hamburg [video]

https://www.youtube.com/watch?v=hqUItF7m3tk
1•pjmlp•1h ago•0 comments

Review: 50 Years of Text Games, by Aaron Reed

https://www.thepsmiths.com/p/review-50-years-of-text-games-by
1•NewCzech•1h ago•0 comments

Multiple commencement speakers booed for AI comments during graduation speeches

https://www.nbcnews.com/video/multiple-commencement-speakers-booed-for-ai-comments-during-graduat...
20•wrxd•1h ago•1 comments

Harmony Infra Ventures Reflects the Leadership of Harmandeep Singh Kandhari

https://sites.google.com/view/harmandeep-singh-kandhari
1•KirtiKKapoor•1h ago•1 comments

Screen record more – Applied Cartography

https://www.jmduke.com/posts/screen-record-more.html
1•rhazn•1h ago•0 comments

The just-say-no engineer was a ZIRP phenomenon

https://www.seangoedecke.com/the-just-say-no-engineer-was-a-zirp-phenomenon/
2•rhazn•1h ago•0 comments