frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Post Peek – Litterbox-Inspired Tweet Viewing Extension for Chrome

https://daringfireball.net/linked/2026/09/12/post-peek
1•JumpCrisscross•25s ago•0 comments

Artor.app – Deploy prototypes and have Figma-style comments directly on them

https://artor.app
1•AleSch•25s ago•0 comments

Is China's growth model bad for its own people?

https://www.chat-gdp.org/p/is-chinas-growth-model-bad-for-its
1•alphabetatango•58s ago•0 comments

Litterbox: XCancel for iOS and Mac

https://andadinosaur.com/launch-litterbox
1•JumpCrisscross•2m ago•0 comments

Component Hashes in SBOMs

https://worklifenotes.com/2026/09/14/component-hashes-in-sboms/
1•taleodor•4m ago•0 comments

Claude Code Over 6k issues labeled with has repro have been auto-closed

https://github.com/anthropics/claude-code/issues/87647
4•antropic13224ad•6m ago•0 comments

Sportacus

https://en.wikipedia.org/wiki/Sportacus
2•softwaredoug•6m ago•0 comments

A list of 1,325 AI assisted repositories, mined from GitHub

https://github.com/ActuallyTaylor/strata/blob/main/paper/data/large/datasets/ai-assisted-reposito...
2•ActuallyTaylor•7m ago•0 comments

Can a regex match valid credit card numbers?

https://abstractnonsense.xyz/blog/2025-08-31-can-a-regex-match-valid-card-numbers/
1•fanf2•7m ago•0 comments

'Project Lily': The Humans Reading Your ChatGPT Chats

https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/
2•2sf5•8m ago•0 comments

RubyGems Open Source Supply Chain Security and OpenAI

https://rietta.com/blog/rubygems-supply-chain-openai/
3•rietta•10m ago•0 comments

Show HN: What an agent does when anyone can read and rewrite its context

https://ljedrz.github.io/nachalnik/
2•ljedrz•11m ago•0 comments

Qwen 3.8 Flash via DwarfStar

https://twitter.com/antirez/status/2099487927793299936
2•hmokiguess•11m ago•0 comments

Jabber/XMPP: How Do We Gain Traction?

https://gultsch.de/posts/how-do-we-gain-traction/
5•inputmice•11m ago•0 comments

1,000+ shoes reviewed and cut in half

https://runrepeat.com
2•bushwart•12m ago•0 comments

More Money Than They Ever Imagined–and No Clue How to Spend It

https://www.wsj.com/tech/ai/ai-tech-anthropic-openai-ipo-0a9da59e
1•Jimmc414•13m ago•1 comments

Cheap high brand (armani,Nike,Jordan etc.)

https://cheapmarketprices.com/
1•ilaysyou•13m ago•0 comments

Buy Intel, It's Cheap

3•roschdal•13m ago•0 comments

Show HN: Voice Rater – in-browser voice analysis (jitter, CPPS, formants)

https://voice-rater.com/
2•hacksu•13m ago•0 comments

Borrow Checking, RC, GC, and the Eleven Other Memory Safety Approaches (2024)

https://verdagon.dev/grimoire/grimoire
2•Tomte•14m ago•0 comments

With dead oysters and debt, PEI farmers fear they'll lose everything

https://www.cbc.ca/radio/thecurrent/oyster-farmers-msx-dermo-9.7337251
2•JumpCrisscross•14m ago•0 comments

Ars Magna (Cardano Book)

https://en.wikipedia.org/wiki/Ars_Magna_(Cardano_book)
1•vismit2000•15m ago•0 comments

Oslo bans smart glasses in schools

https://www.thelocal.no/20260910/oslo-bans-smart-glasses-in-schools
3•bushwart•15m ago•0 comments

Removing algorithmic feed slop from my life

https://bell.bz/removing-algorithmic-feed-slop-from-my-life/
2•speckx•15m ago•0 comments

Dynamicz

https://opentofu.org/blog/opentofu-1-12-0/
1•starlightsmovem•16m ago•0 comments

A rough guide for going back to the Moon

https://research.ibm.com/blog/nasa-ibm-lunar-foundation-model
2•gmays•16m ago•0 comments

The Only Crypto Story You Need, by Matt Levine (2022)

https://www.bloomberg.com/features/2022-the-crypto-story/
1•Tomte•19m ago•0 comments

Two Wrong Answers, One Exact Solution: The Arithmetic Method Schools Forgot

https://valeman.medium.com/two-wrong-answers-one-exact-solution-the-arithmetic-method-schools-for...
2•ibobev•19m ago•0 comments

Show HN: PHP-fts 2.0 – Pure-PHP full-text search, now in 26 writing systems

https://github.com/olivier-ls/php-fts/releases/tag/v2.0.0
1•asmodios•19m ago•0 comments

Most people prefer traditional architecture

https://www.worksinprogress.news/p/do-people-prefer-traditional-architecture
2•alihm•19m ago•0 comments