frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Gone but Not Forgotten: Recovering the Dead Web

https://blog.archive.org/2026/04/23/gone-but-not-forgotten-recovering-the-dead-web/
2•wslh•4m ago•0 comments

Fedora 45 Looks to Offer Install Support for Stratis Storage

https://www.phoronix.com/news/Fedora-45-Stratis-Storage
1•rbanffy•4m ago•0 comments

Grok translated my coworker's tweet as sexualized

1•aizk•6m ago•0 comments

The dress

https://en.wikipedia.org/wiki/The_dress
1•tejohnso•6m ago•0 comments

Trump's plan to redesign every .gov website leads to AI-designed horrors

https://arstechnica.com/tech-policy/2026/06/trumps-plan-to-redesign-every-gov-website-leads-to-ai...
1•rbanffy•6m ago•0 comments

Bringing Claude Code into Neovim

https://inacioklassmann.com/posts/claude-chat-nvim/
1•samsgro•6m ago•0 comments

Ship traces journey Spanish Armada sailors made in 1588

https://www.irishtimes.com/ireland/2026/06/30/it-is-a-huge-honour-ship-traces-journey-spanish-arm...
1•austinallegro•7m ago•0 comments

Addsong: Paste a link, song appears in Apple Music with full metadata and art

https://github.com/ado11231/addsong
1•ado11231•7m ago•0 comments

AMD Stretches Server DRAM with Flash Extended Memory

https://www.nextplatform.com/store/2026/06/29/amd-stretches-server-dram-with-flash-extended-memor...
1•rbanffy•8m ago•0 comments

Fear and Loathing in Python: Building a Distributed Context System for Wool

https://gist.github.com/conradbzura/885a542ff0ccd548aa16fd05525a7a71
1•bzurak•10m ago•1 comments

Big Tech's 13 Most Interesting Patents This Week

https://patentlyze.substack.com/p/needle-free-blood-monitoring-a-mirror
2•Dfol•11m ago•0 comments

How to Build a Winning Go-to-Market Strategy for Latam

https://expansionamericas.com/how-to-build-a-winning-go-to-market-strategy-for-latam
1•joserparamo•13m ago•0 comments

CIA Reorganization Prioritizes Cyberoperations

https://www.nytimes.com/2026/06/30/us/politics/cia-reorganization-cyber-ai.html
2•ChrisArchitect•15m ago•0 comments

Show HN: Turning Sentry errors into AI generated GitHub PRs with fixes

https://bugzero.dev
2•rafalswietek•16m ago•1 comments

US Army Women Are More Likely to Be Killed by Army Men Than by War

https://theintercept.com/2026/06/30/army-women-death-domestic-violence-sexual-assault/
5•rendx•21m ago•1 comments

NPR retracts story about Alito retirement

https://www.npr.org/sections/npr-public-editor/2026/06/30/g-s1-131107/npr-retracts-story-about-al...
2•petethomas•21m ago•0 comments

Daily step count of remote workers associated with lower stress and better work

https://medicalxpress.com/news/2026-06-daily-remote-workers-stress.html
3•OutOfHere•22m ago•0 comments

Show HN: Mimir – local-first encrypted memory for AI agents (single Rust binary)

https://github.com/Perseus-Computing-LLC/mimir
1•perseusai•23m ago•1 comments

Understanding lattice risks: Many differences between marketing and reality

https://blog.cr.yp.to/20260630-risk.html
2•ledoge•23m ago•0 comments

Meta's brain-scanning system reads sentences non-invasively, code open source

https://ai.meta.com/blog/brain2qwerty-brain-ai-human-communication/?_fb_noscript=1
15•alok-g•23m ago•4 comments

Superpowers 6

https://blog.fsck.com/2026/06/15/Superpowers-6/
2•seahorseemoji•24m ago•0 comments

Breaking the Bird Barrier: Scientist Decodes Zebra Finch Language

https://www.freepressjournal.in/education/breaking-the-bird-barrier-scientist-decodes-zebra-finch...
1•yyyk•25m ago•0 comments

Wearable foundation models: a brief history

https://www.empirical.health/blog/wearable-foundation-models/
2•brandonb•26m ago•1 comments

May in Servo: user scripts, mp4 compat, blackboxing in DevTools, and more

https://servo.org/blog/2026/06/30/may-in-servo/
1•birdculture•27m ago•0 comments

Go 1.26 Fixed the Things That Were Annoying

https://towardsdev.com/go-1-26-quietly-fixed-the-things-that-were-actually-annoying-5b4876071f04
2•cheikhdev•27m ago•0 comments

FluidVoice - Open source voice-to-text dictation app for macOS with local AI

https://github.com/altic-dev/FluidVoice
1•danboarder•28m ago•0 comments

MS admits 8GB RAM is fine for Win11, after years of pushing 16GB as the baseline

https://www.windowslatest.com/2026/06/25/microsoft-now-says-8gb-ram-is-fine-for-everyday-use-righ...
3•voxadam•31m ago•1 comments

Tell HN: Amazon Linux 2 is EOL today

https://aws.amazon.com/amazon-linux-2/faqs/
2•theschmed•33m ago•1 comments

Ray Tracer in SQL

https://github.com/ClickHouse/RayTracer
2•kbumsik•34m ago•0 comments

Baseline brain scan predicts adolescent depression and anxiety one year later

https://www.medrxiv.org/content/10.64898/2026.06.08.26355206v1
1•Anon84•36m ago•0 comments