frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Ask HN: What are the machine requirements for a LLM like Llama-3.1-8B?

1•wasimsk•1m ago•0 comments

Reed Hastings to step down from Netflix board

https://www.theguardian.com/media/2026/apr/16/netflix-chair-reed-hastings
1•abawany•1m ago•0 comments

Single Stage Rocket Technology (SSRT) Delta Clipper Experimental (DC-X)(1993) [video]

https://www.youtube.com/watch?v=J6ZyDSmC-d0
1•o4c•5m ago•0 comments

Engram – context spine for AI coding agents, 88% proven token savings

https://github.com/NickCirv/engram
1•NickCirv•5m ago•0 comments

Deleteduser.com – A $15 PII Magnet

https://mike-sheward.medium.com/deleteduser-com-a-15-pii-magnet-c4396eb21061
2•p4bl0•10m ago•1 comments

MongoDB Compass Alternative

https://visualeaf.com/blog/visualeaf-as-mongodb-compass-alternative/
1•RoxiHaidi•12m ago•0 comments

I'm tired about hearing about AI startups

1•geuis•18m ago•2 comments

Observational constraints project a ~50% AMOC weakening by end of this century

https://www.science.org/doi/10.1126/sciadv.adx4298#sec-3
1•Kaibeezy•18m ago•0 comments

Drivers sue San Jose over nearly 500 police cameras used to track drivers

https://www.nbcnews.com/tech/tech-news/san-jose-drivers-sue-city-police-flock-cameras-rcna331750
2•blessedwhiskers•20m ago•0 comments

IETF: Meow

https://www.ietf.org/archive/id/draft-meow-mrrp-00.html
1•michaelsshaw•23m ago•0 comments

Dog Bed Database

https://aosabook.org/en/500L/dbdb-dog-bed-database.html
2•tosh•24m ago•0 comments

Why is the unit of measure placed before the value for currencies? (2016)

https://english.stackexchange.com/questions/34013/why-is-the-unit-of-measure-placed-before-the-va...
2•fittingopposite•25m ago•1 comments

'Middle Class' Actors Are Getting 'Squeezed Out' of Hollywood

https://variety.com/2026/tv/news/kirk-acevedo-sold-house-middle-class-actors-hollywood-1236722809/
3•Michelangelo11•25m ago•0 comments

House punts on FISA, extends spy powers program for two weeks

https://www.politico.com/news/2026/04/17/spy-powers-expiration-closes-in-as-house-procedural-vote...
1•Cider9986•26m ago•0 comments

A Stunning New Verdict Rewrites the Rules of Corporate Morality

https://www.nytimes.com/2026/04/17/opinion/a-stunning-new-verdict-rewrites-the-rules-of-corporate...
1•mitchbob•26m ago•1 comments

First bikebell against noise-canceling headphones

https://www.welovecycling.com/wide/duobell/
2•mccolly•28m ago•0 comments

Intel Core Ultra 7 270K Plus Performance in 340 Linux Benchmarks Review

https://www.phoronix.com/review/intel-core-ultra-7-270k-plus
2•rbanffy•29m ago•0 comments

How Secure Is Tap to Pay? [Veritasium] [video]

https://www.youtube.com/watch?v=PPJ6NJkmDAo
1•mfrw•30m ago•0 comments

For Enterprises, GPUs Need Virtualization as Much as CPUs Ever Did

https://www.nextplatform.com/control/2026/04/10/for-enterprises-gpus-need-virtualization-as-much-...
1•rbanffy•34m ago•0 comments

Everything works. Until it doesn't

https://blog.bridgexapi.io/everything-works-until-it-doesn-t-what-changes-when-messaging-hits-scale
1•Bridgexapi•34m ago•1 comments

PROBoter – Open-source platform for automated PCB analysis

https://www.schutzwerk.com/en/blog/proboter-01/
2•kuizu•36m ago•0 comments

US tech firms lobbied EU to keep datacentre emissions secret

https://www.theguardian.com/technology/2026/apr/17/microsoft-us-tech-firms-lobbied-eu-secrecy-rul...
2•zeristor•38m ago•1 comments

Ask HN: DS920 –> Unraid build, is the flexibility worth it?

1•sidebotexp•38m ago•0 comments

Search 54M Discord messages by User ID –> see cross-server history

https://illumi.icu/
1•NotTenyear•38m ago•2 comments

Ephemeral Leaks and Automated BGP Route Leak Detection

https://www.kentik.com/blog/ephemeral-leaks-and-automated-bgp-route-leak-detection/
1•oavioklein•39m ago•0 comments

McDonnell Douglas DC-X(1993)

https://en.wikipedia.org/wiki/McDonnell_Douglas_DC-X
2•o4c•39m ago•0 comments

Does your DSL little language need operator precedence?

https://utcc.utoronto.ca/~cks/space/blog/programming/LittleLanguagesVsOpPrecedence
1•ingve•43m ago•0 comments

UC Berkeley talk from alum CVP Microsoft on jobs, startups, and coding agents [video]

https://www.youtube.com/watch?v=l3RTCyMeceM
2•sfrcom•45m ago•1 comments

Qodiqa Consent as Infrastructure for Artificial Intelligence

https://qodiqa.github.io/qodiqa/docs/QODIQA___Consent_as_Infrastructure_for_Artificial_Intelligen...
1•bogdandutescu•45m ago•0 comments

Intel refreshes non-Ultra Core CPUs with new silicon for the first time

https://arstechnica.com/gadgets/2026/04/intels-non-ultra-core-cpus-are-new-silicon-this-year-for-...
1•rbanffy•45m ago•0 comments