frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Making JsDelivr's Origin More Reliable at Scale

https://www.jsdelivr.com/blog/making-jsdelivrs-origin-more-reliable-at-scale/
1•jimaek•1m ago•0 comments

Breaking the M365 Copilot Sandbox with ChatMate

https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate
1•shivanshuag•2m ago•0 comments

Show HN: PicPocket – Dedicated 'chats' for photo-sharing (share to organize)

https://picpocket.io/
1•amr_shawky•2m ago•0 comments

A dating app inside Claude Code

https://terminal.dating
1•welshpony•2m ago•0 comments

We migrated off Enzyme in 2 weeks. It should have taken five years

https://asana.com/inside-asana/migrating-off-enzyme-2-weeks
1•pspeter3•3m ago•0 comments

China Bets on AI Stocks as It Races Against US for Chip, Tech Dominance

https://www.bloomberg.com/news/features/2026-08-09/china-bets-on-ai-stocks-as-it-races-against-us...
2•evo_9•6m ago•0 comments

Frost-GKR: a global trace protocol for batched Poseidon2B

https://lab.parano1d.org/research/frost-gkr-global-trace-protocol/
2•ignotusnemo•9m ago•0 comments

Exploiting System Management Mode with a very long interrupt

https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii
2•WhiteDawn•9m ago•0 comments

GLP-1 drugs linked to bigger jump in women’s employment than a college degree

https://finance.yahoo.com/healthcare/articles/harvard-study-links-glp-1-123000637.html
5•metadat•10m ago•0 comments

Kyverno Policies to Secure Your Kubernetes Cluster

https://medium.com/@devarshidev/5-kyverno-policies-to-secure-your-kubernetes-cluster-9fdbf971b7b2
2•devarshishimpi•11m ago•0 comments

Autoscaling MirageOS Unikernels in Mollymawk

https://blog.robur.coop/articles/2026-07-08-Autoscaling-MirageOS-unikernels-in-Mollymawk.html
3•andrewstetsenko•12m ago•0 comments

Trust is all you need, and all we've lost

https://r5d.me/trust-and-the-lack-thereof/
3•solaire_oa•13m ago•0 comments

Show HN: Ante, a coding agent in a single binary that runs offline

https://github.com/AntigmaLabs/ante
3•ubermon•13m ago•1 comments

Back to the Future of Handwriting Recognition

https://jackschaedler.github.io/handwriting-recognition/
3•at1as•14m ago•0 comments

Historical Discoveries That Reshaped Modern Historical Understanding

https://thehistoricalinsights.page/2026/08/historical-discoveries.html
2•historical1234•17m ago•0 comments

A macOS app for customizing which browser to start

https://github.com/johnste/finicky
2•mooreds•17m ago•0 comments

The Tragedy of the Cognitive Commons

https://arxiv.org/abs/2607.29380
2•jmintz•17m ago•0 comments

Show HN: Bio Tools – install drug design tools easily

https://github.com/David-OConnor/bio_tools
2•the__alchemist•17m ago•0 comments

Midlife Vascular Risk Burden and Dementia-Free Survival Years

https://www.neurology.org/doi/10.1212/WN9.0000000000000152
2•bookofjoe•18m ago•0 comments

Automatia Update: Next of Kin

https://libriscv.no/blog/next-of-kin/
2•fwsgonzo•18m ago•0 comments

A California Program Is Bringing Down the Cost of Heat Pumps by Buying Bulk

https://www.wired.com/story/california-group-buy-bringing-down-heat-pump-costs/
2•Brajeshwar•19m ago•0 comments

4 hours and 37 minutes of serving nothing

https://koleslaw.ai/blog/running-a-30b-model-on-spot-gpus
3•murphman•19m ago•0 comments

The Great Chinese Oil Mystery

https://www.theatlantic.com/economy/2026/07/china-iran-usa-oil-prices/688086/
3•alphabetatango•19m ago•1 comments

Show HN: MergeImage – merge and stitch images locally in the browser

https://mergeimage.app/
2•lby910722•20m ago•0 comments

Extreme 220GHz+Broadband Silicon Capacitor X2SC 0201M 22nF BV11

https://pim.murata.com/asset/pim4/siliconCapacitor/SICAP_X2SC422522_PDF_SILICONCAPACITOR
2•peter_d_sherman•20m ago•0 comments

Why Open Source Matters for AI: Models should be infrastructure, not appliances

https://oreillyradar.substack.com/p/why-open-source-matters-for-ai
2•dbreunig•21m ago•0 comments

Japan and the US Supported the Yen Last Week

https://www.emergingtrajectories.com/lh/us-japan-yen-intervention/
2•cl42•22m ago•2 comments

We Got Better at Keeping You Alive. Not at Keeping You Healthy

https://julienreszka.com/blog/we-got-better-at-keeping-you-alive-not-at-keeping-healthy/
2•julienreszka•22m ago•0 comments

Controversial Bitcoin fork BIP-110 mines two blocks, then stops

https://www.coindesk.com/tech/2026/08/09/controversial-bitcoin-fork-bip-110-mines-two-blocks-then...
3•HardwareLust•22m ago•0 comments

China-Free Batteries Made from Salt Are Finally Here

https://www.wsj.com/business/energy-oil/china-free-batteries-made-from-salt-are-finally-here-cc1c...
3•inferhaven•22m ago•2 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.