frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

"Drawing" the Mona Lisa with GPT-5.6, Claude, Gemini, and Grok

https://www.tryai.dev/blog/ai-drawing-arena-colored-pencils-claude-gpt-grok
1•hershyb_•27s ago•0 comments

Where do the biggest diamonds come from? Geology now has answers

https://theconversation.com/where-do-the-worlds-biggest-diamonds-come-from-geology-now-has-answer...
1•bryanrasmussen•1m ago•0 comments

Short positions in SpaceX reach 32% of float

https://www.cnbc.com/2026/07/21/bets-against-spacex-grow-to-32percent-of-float-as-elon-musk-warns...
1•darth_avocado•2m ago•0 comments

Oracle critical July patch update advisory contains 1,449 new security patches

https://www.oracle.com/security-alerts/cpujul2026.html
1•speckx•4m ago•0 comments

A digestion of the Jacobian conjecture counterexample

https://terrytao.wordpress.com/2026/07/21/a-digestion-of-the-jacobian-conjecture-counterexample/
3•jeremyscanvic•4m ago•0 comments

Bring Your Own Harness

https://andreapivetta.com/posts/bring-your-own-harness.html
1•ziggy42•4m ago•0 comments

K0s – The Zero Friction Kubernetes

https://github.com/k0sproject/k0s
1•porjo•6m ago•0 comments

Show HN: RootBadger – a modern Usenet-style discussion platfor

https://rootbadger.com
1•yodabytz•7m ago•0 comments

Treasury Flags Concern over 'Potentially Abusive' Tax Trades

https://www.bloomberg.com/news/articles/2026-07-21/treasury-flags-concern-over-potentially-abusiv...
1•petethomas•7m ago•0 comments

Nvidia Vera Rubin Driving Performance per Watt, Lowest Token Cost for Partners

https://www.hpcwire.com/off-the-wire/nvidia-vera-rubin-driving-performance-per-watt-lowest-token-...
2•rbanffy•8m ago•0 comments

Show HN: Browser Tools SDK – an optimal browser harness for agents

https://libretto.sh/browser-tools
2•tanishqkanc•11m ago•0 comments

Show HN: Unified workspace where AI knows your business

https://zetadeck.com
1•not_wowinter13•11m ago•0 comments

iOS 27 code suggests Apple could restrict leased devices after missed payments

https://9to5mac.com/2026/07/21/ios-27-code-suggests-apple-could-restrict-leased-devices-after-mis...
1•cdrnsf•12m ago•0 comments

Ask HN: What is your onboarding/discovery process for a new client or project?

1•urnicus•13m ago•0 comments

Octen: We stayed quiet and built the fastest search on Earth

https://twitter.com/KZouAPT/status/2079569508549673409
2•devchandra•15m ago•3 comments

Show HN: Meltbox – where your agents send you briefs

https://meltbox.ai/
1•flysonic10•17m ago•0 comments

MovieSoon: What's coming to a theater near you

https://moviesoon.eu/
2•taubek•17m ago•0 comments

Cisco Antares: A New Family of Cheap, Open-Source, Compact Security AI Models

https://securityboulevard.com/2026/07/cisco-antares-a-new-family-of-open-source-inexpensive-compa...
4•CrankyBear•18m ago•0 comments

Nintendo says users voluntarily paid prices, have no right to tariff refunds

https://arstechnica.com/tech-policy/2026/07/nintendo-customers-have-no-legal-right-to-tariff-refu...
3•AdmiralAsshat•18m ago•1 comments

Supporting ATI TeraScale GPUs from 2007-2009 in RPCS3

https://blog.rpcs3.net/2026/07/21/supporting-terascale-gpus/
1•ColonelPhantom•18m ago•0 comments

Oratomic's $300M Bet on Low-Qubit Quantum Computing

https://www.hpcwire.com/2026/07/21/oratomics-300m-bet-on-low-qubit-quantum-computing/
1•rbanffy•19m ago•0 comments

Worship me at the office altar: Why narcissistic leaders resist remote work

https://www.sciencedirect.com/science/article/pii/S0749597826000300#kg005
4•Tomte•20m ago•1 comments

Anthropic runs large-scale code migrations with Claude Code

https://twitter.com/ClaudeDevs/status/2079654423828304282
2•shenli3514•21m ago•0 comments

Bill Gates Is Evil (2021)

https://windows-99.neocities.org
3•Gecko4072•21m ago•0 comments

Flux 3 seems to be imminent

https://bfl.ai/models/flux-3
3•recsv-heredoc•22m ago•1 comments

How Far Behind the Frontier Are Leading Open Weight Models on Cyber?

https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber
1•herbertl•24m ago•0 comments

GE Aerospace aircraft flies to mark high altitude hybrid-electric milestone

https://www.aerospacetestinginternational.com/news/ge-aerospace-aircraft-flies-at-farnborough-to-...
1•rbanffy•24m ago•0 comments

Mickey Mouse Sells a Bundle

https://www.marginpoints.com/essays/mickey-mouse-sells-a-bundle-hn
4•historian1066•25m ago•0 comments

First-ever X-rays in space offer hope for possible patients headed to the moon

https://www.space.com/space-exploration/human-spaceflight/1st-ever-x-rays-in-space-offer-hope-for...
1•gmays•25m ago•0 comments

The future of software isn't tests. It's proofs

https://github.com/astrio-labs/forall
7•Nolan_Lwin•26m ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.