frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: Shdoc – javadoc for shell scripts (2019)

https://github.com/reconquest/shdoc
1•reconquestio•7m ago•0 comments

Complexity Theory's 50-Year Journey to the Limits of Knowledge (2023)

https://www.quantamagazine.org/complexity-theorys-50-year-journey-to-the-limits-of-knowledge-2023...
1•arunc•9m ago•0 comments

Future Prediction of News Letter

https://pendianoca.substack.com/p/the-friction-filled-transition-maritime
1•penpendian•11m ago•0 comments

Surface Laptop Ultra: Made for World Makers

https://blogs.windows.com/devices/2026/05/31/introducing-surface-laptop-ultra-made-for-world-makers/
3•berlianta•11m ago•0 comments

MiniMax M3: The First Open-Weights Model to Combine Three Frontier Capabilities

https://twitter.com/MiniMax_AI/status/2061266317815296322
3•pretext•16m ago•0 comments

Comparisons of Health Care Systems in the United States, Germany and Canada (2012)

https://pmc.ncbi.nlm.nih.gov/articles/PMC3633404/
1•rawgabbit•16m ago•0 comments

Story Points: Explicit, Honest, Predictable. In Use

https://bastrich.tech/story-points/
1•bastrich•18m ago•0 comments

Hermes Agent is now natively supported on Windows

https://hermes-agent.nousresearch.com/docs/user-guide/windows-native
1•pretext•18m ago•0 comments

Ask HN: What's an advice that you no longer give? Why?

2•joddystreet•20m ago•0 comments

Gavriel Cohen found his own code inside OpenClaw, so he walked away

https://thenewstack.io/nanoclaw-openclaw-agent-security/
1•msolujic•20m ago•0 comments

Jk

https://marcodonatodigitalluxe.nl/
1•janbv124•26m ago•0 comments

SOTA-scan: Claude skill, an honest mirror for your repo

https://github.com/MerlijnW70/sota-scan
1•MerlijnW70•29m ago•0 comments

"What a joke": GitHub Copilot's token-based billing spurs backlash among devs

https://techcrunch.com/2026/05/30/what-a-joke-github-copilots-new-token-based-billing-spurs-const...
2•nryoo•30m ago•0 comments

Prompt injection lets attackers hijack Instagram accounts via Meta AI support

https://www.neowin.net/news/people-are-using-prompt-injection-to-trick-metas-ai-into-handing-over...
2•bundie•30m ago•0 comments

The Capacity of HotHands to Facilitate High-Altitude Research (2023) [pdf]

https://www.colorado.edu/center/spacegrant/sites/default/files/attached-files/B3_RRCC_BringingThe...
2•radeeyate•32m ago•0 comments

Rubin Tracks Skyscraper-Size Asteroids and Failed Supernovas

https://www.quantamagazine.org/rubin-tracks-skyscraper-size-asteroids-failed-supernovas-and-inter...
2•adm4•36m ago•0 comments

Reflection SDD: Use a Reflection Harness to Level Up Your OpenSpec Workflow

https://www.dataleadsfuture.com/reflection-sdd-use-a-reflection-harness-to-level-up-your-openspec...
1•qtalen•38m ago•1 comments

The first Vera Rubin NVL72 server rack

https://twitter.com/i/status/2061118201636036668
3•mudil•59m ago•0 comments

Marcus Aurelius Had Anxiety Too – Stoicism for People Who Overthink

https://stvrrll1ght.substack.com/p/marcus-aurelius-had-anxiety-too-stoicism
11•maheenahmed•1h ago•1 comments

In UFO Files, Some Christians See Vexing Questions – and Demons

https://www.nytimes.com/2026/05/31/us/ufo-files-pentagon.html
1•ryan_j_naughton•1h ago•0 comments

Can I find the exact number of users in FusionAuth with specific attributes?

https://fusionauth.io/community/forum/topic/3132/how-can-i-get-an-exact-number-of-users-with-some...
1•mooreds•1h ago•0 comments

Ask HN: How do you solve AI's confused deputy problem?

1•david_shi•1h ago•0 comments

xAI touts 10x performance gain while Ceramic has achieved 80 MFU

https://www.ceramic.ai/blog/ai-training-stack-performance-how-ceramic-achieved
4•densone•1h ago•0 comments

The Totalisator

https://computer.rip/2026-05-31-totalisator.html
2•pinewurst•1h ago•0 comments

Peter Thiel warns AI is threat to technical roles more than to creative thinkers

https://fortune.com/article/peter-thiel-ai-skills-creative-thinking-technical/
5•1vuio0pswjnm7•1h ago•1 comments

Nearly one-third of automotive loan terms are longer than six years

https://www.businesswire.com/news/home/20260528635242/en/
2•mattas•1h ago•1 comments

Instagram exploit allows you to use Meta AI to reset passwords to accounts

https://xcancel.com/DarkWebInformer/status/2061253599758315527
3•Cider9986•1h ago•0 comments

Show HN: Find your birth date song that was number-one

https://github.com/skorotkiewicz/tbs
1•modinfo•1h ago•0 comments

The Grand Unified Model of DevOps/SRE Dynamics

https://sigbovik.org/2026/proceedings.pdf#page=897
2•ycombiredd•1h ago•2 comments

Weekend trivia: your process' memory is a file

https://lcamtuf.substack.com/p/weekend-trivia-your-process-memory
3•surprisetalk•1h ago•0 comments