frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

We are in the golden age of Open Source

https://kerkour.com/open-source-golden-age-ai
1•worik•6m ago•0 comments

MySQL 9.7.0 LTS Is Now Available

https://blogs.oracle.com/mysql/mysql-9-7-0-lts-is-now-available-expanded-community-capabilities-a...
1•ksec•6m ago•0 comments

Show HN: Aegis – post-quantum cyberdefense proxy (471 attacks, 0 breaches)

https://github.com/conchaestradamiguelangel-droid/aegis
1•conchaestrada•10m ago•0 comments

They are looting your life savings

https://social.bau-ha.us/@raganwald/116705256401454865
11•ColinWright•12m ago•4 comments

They Already Need a Bailout

https://www.youtube.com/watch?v=QAn_39-qu6I
3•tcp_handshaker•14m ago•0 comments

The mysterious database that provides clues to China's foreign surveillance

https://www.smh.com.au/world/asia/the-mysterious-database-that-provides-clues-to-china-s-foreign-...
1•cwwc•17m ago•0 comments

No More Hidden Changes: How MySQL 9.6 Transforms Foreign Key Management

https://blogs.oracle.com/mysql/no-more-hidden-changes-how-mysql-9-6-transforms-foreign-key-manage...
1•ksec•17m ago•0 comments

The Dictionary of Obscure Sorrows

https://www.thedictionaryofobscuresorrows.com
2•mhb•18m ago•0 comments

Add a Little Something to the CSS

https://codeberg.org/gedankenstuecke/pages-source/commit/57f7df832d45eb847d1a0af3cca2f3ab81585a2c
1•ColinWright•19m ago•0 comments

Ask HN: How to get my contact info off US political party's list

1•kaycebasques•19m ago•0 comments

An engine-run runtime environment for data sovereignty

https://www.trinitymonolith.io/
1•rahkyt•21m ago•0 comments

Ukrainian Drone Strikes Target Russian Military Facilities in St. Petersburg

https://www.wsj.com/world/russia/mass-ukrainian-drone-strikes-target-russian-military-facilities-...
2•JumpCrisscross•21m ago•0 comments

Database as a Graph for Relational Deep Learning

https://neovintage.org/posts/relational-deep-learning/
1•neovintage•23m ago•0 comments

Programmers Aren't People

https://elliotbonneville.com/programmers-arent-people/
2•elliotbnvl•24m ago•0 comments

Gothic 1 Remake

https://store.steampowered.com/app/1297900/Gothic_1_Remake/
1•doener•25m ago•0 comments

Alley Cat (IBM, 1984)

https://www.playdosgames.com/online/alley-cat/
1•reconnecting•27m ago•0 comments

2026 Methods for Free Compute and AI Credits

https://www.dropbox.com/scl/fi/bvi5v0i94ifnk3mfstewq/SAIRC-Free-Compute.pdf?dl=0&e=1&noscript=1&r...
1•imranmk•31m ago•0 comments

Decoupled RISC-LLM Architectures via Circadian Synaptic Consolidation

https://aermia.com/u/NancySadkov/p/research-proposal-decoupled-risc-llm-architectures-via-circadi...
1•NancySadkov•33m ago•0 comments

AI could drive advances that solve problems it brings, scientist suggests

https://www.rnz.co.nz/news/science-and-technology/597458/ai-could-drive-advances-that-solve-the-p...
3•billybuckwheat•37m ago•0 comments

Why Robotics Is a Pre-Paradigm Field

https://whattotelltherobot.com/p/why-robotics-is-a-pre-paradigm-field
2•stefie10•39m ago•0 comments

NEOM issues temporary work stoppage on The Line until at least 2030

https://www.archpaper.com/2026/06/neom-temporary-work-pause-the-line/
2•JumpinJack_Cash•39m ago•0 comments

The C++ Documentary Won't Show You a Number. I Will

https://hftuniversity.com/post/the-c-documentary-won-t-show-you-a-number-i-will
3•canyp•44m ago•1 comments

Wasting China's solar panel surplus is madness

https://www.ft.com/content/b6cac184-75a4-47ab-94c5-5eb8c92cd407
4•mmarian•45m ago•3 comments

Criticizing the Everything Machine

https://pluralistic.net/2026/06/06/applied-counterescatology/
1•hn_acker•47m ago•0 comments

Refining Humanity

https://pluralistic.net/2026/06/05/defining-humanity/
1•hn_acker•47m ago•0 comments

Show HN: Dap-mux – Connect your editor and REPL to the same debug session

1•YesJustWolf•49m ago•0 comments

DOGE plan would have marked 2.7M living people as dead: Whistleblower

https://thehill.com/homenews/nexstar_media_wire/5912841-doge-plan-would-have-marked-2-7m-living-p...
6•hn_acker•49m ago•0 comments

William Gass and John Hawkes (1971)

https://www.92ny.org/archives/william-gass-and-john-hawkes
1•ofalkaed•50m ago•0 comments

Useful Robots (1968) [video]

https://www.youtube.com/watch?v=cEbSaWNs9pY
2•megamike•52m ago•0 comments

Show HN: PriceHound.app – Price tracking for $1/mo instead of selling your data

3•Brian_Fitz•58m ago•0 comments