frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•12mo ago

Comments

kemotep•12mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Is Italy the new tax haven for the global rich?

https://www.bbc.com/worklife/article/20260421-is-italy-the-new-tax-haven-for-the-global-rich
1•andsoitis•3m ago•0 comments

Jeff Bezos is raising his game in space

https://www.economist.com/business/2026/04/23/jeff-bezos-is-raising-his-game-in-space
1•andsoitis•4m ago•0 comments

Bdelloid Rotifer

https://en.wikipedia.org/wiki/Bdelloidea
1•embedding-shape•5m ago•0 comments

Tim Cook wrote a winning recipe for Apple

https://www.economist.com/leaders/2026/04/23/tim-cook-wrote-a-winning-recipe-for-apple
1•andsoitis•6m ago•0 comments

Peter Sarnak – The Riemann Hypothesis [video]

https://www.youtube.com/watch?v=DtaFyE9BcXw
1•delhanty•9m ago•1 comments

Google is building a Claude Code challenger, Sergey Brin is involved

https://www.indiatoday.in/technology/news/story/google-is-secretly-building-a-claude-code-challen...
1•nsoonhui•14m ago•0 comments

Michael review: 'A bland and barely competent daytime TV movie'

https://www.bbc.com/culture/article/20260421-michael-review
1•dnnddidiej•23m ago•0 comments

Education must go beyond the mere production of words

https://www.ncregister.com/commentaries/schnell-repairing-the-ruins
2•signor_bosco•26m ago•0 comments

Decoupled DiLoCo for Resilient Distributed Pre-Training

https://arxiv.org/abs/2604.21428
1•matt_d•31m ago•0 comments

Serendipity Machines

https://www.shishyko.com/essays/serendipity-machines.html
1•philip1209•35m ago•0 comments

Mac-use: open-source Codex computer-use clone for your OpenClaw on Mac OS

https://github.com/TheGuyWithoutH/mac-computer-use
1•guywithnoh•40m ago•2 comments

ChatGPT ads targeting farmers (YouTube Link) [video]

https://www.youtube.com/watch?v=4rzeW4dbvlQ
1•ki4jgt•41m ago•0 comments

Prop 13 Didn't Shrink Government. It Handed It to Sacramento

https://maxmautner.com/2026/04/23/prop-13-changed-things.html
1•mslate•44m ago•0 comments

Why does the Rainbow have 7 colors?

https://glorify.com/learn/why-does-the-rainbow-have-seven-colors
2•airstrike•45m ago•0 comments

You're about to feel the AI money squeeze

https://www.theverge.com/ai-artificial-intelligence/917380/ai-monetization-anthropic-openai-token...
2•cdrnsf•48m ago•1 comments

Anthropic now requires Pro Plans to enable/purchase extra usage for Opus

https://support.claude.com/en/articles/11940350-claude-code-model-configuration
7•qdot76367•50m ago•3 comments

Context Pricing and Accounting [video]

https://www.youtube.com/watch?v=xcYhV4S7faI
1•journal•52m ago•0 comments

Chinese National Pleads Guilty to Photographing Air Force Base and Equipment

https://www.justice.gov/usao-wdmo/pr/chinese-national-pleads-guilty-unlawfully-photographing-air-...
2•737min•55m ago•3 comments

Databases Were Not Designed for This

https://arpitbhayani.me/blogs/defensive-databases/
1•mooreds•56m ago•0 comments

James Bosworth on the 'Orange Wave' Happening Across Latin America

https://www.bloomberg.com/news/articles/2026-04-24/james-bosworth-on-the-orange-wave-happening-ac...
1•mooreds•57m ago•1 comments

Alex Bores' AI Policy Framework for Congress [pdf]

https://www.alexbores.nyc/files/Bores_AI_Framework.pdf
1•mooreds•1h ago•0 comments

Andrej Karpathy's microgpt as a Triptych

https://karpathy.art/
1•stared•1h ago•0 comments

Chinese National Arrested for Illegally Photographing Military Aircraft at AFB

https://www.justice.gov/opa/pr/chinese-national-arrested-jfk-international-airport-federal-charge...
2•737min•1h ago•1 comments

Exodus, from former Mass Effect devs, couldn't look more like Mass Effect

https://www.pcgamer.com/games/rpg/exodus-the-sci-fi-rpg-from-former-mass-effect-devs-couldnt-look...
2•evo_9•1h ago•0 comments

Ancient amber reveals a true bug equipped with claws, a highly unusual feature

https://phys.org/news/2026-04-ancient-amber-reveals-true-bug.html
2•bookofjoe•1h ago•0 comments

The bull case for graph DBs in law

https://alanyahya.com/writing/bull-case-graph-dbs-law
2•alansaber•1h ago•0 comments

Microsoft offers voluntary employee buyout/retirement for 7% of U.S. workforce

https://www.cnbc.com/2026/04/23/microsoft-plans-first-voluntary-retirement-program-for-us-employe...
3•mgh2•1h ago•0 comments

Show HN: RoboAPI – A unified REST API for robots, like Stripe but for hardware

https://github.com/amitb-quantum/roboapi
1•xmas123•1h ago•1 comments

Lumitime Automata – The Most Amazing Digital Clock Is a Machine [video]

https://www.youtube.com/shorts/LTInOMdjs5o
1•thunderbong•1h ago•0 comments

David Choi's Mars FX Collapse Sparks Global Hunt for Almost $600M

https://www.bloomberg.com/news/articles/2026-04-24/hedge-fund-collapse-sparks-global-hunt-for-alm...
1•simonpure•1h ago•1 comments