frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Graphene can be made using a kitchen blender, a mobile phone and a newspaper

https://theconversation.com/the-wonder-material-graphene-can-be-made-using-a-kitchen-blender-a-mo...
1•geox•1m ago•0 comments

New technology lets cloud AI models process your data without privacy leaks

https://plugos.net/blog/2026/08/confidential-ai-how-plugclaw-keeps-your-ai-work-private/
1•ElowenWinslet•2m ago•0 comments

'Don't ask me to print your ChatGPT birthday card': Hitting back at AI 'slop'

https://www.bbc.co.uk/news/articles/cq89jpjeq7ko
1•erehweb•2m ago•0 comments

Hot Chips 2026: Intel's Wildcat Lake

https://chipsandcheese.com/p/hot-chips-2026-intels-wildcat-lake
1•ingve•4m ago•0 comments

Open-Weight Masked Introspection: Measuring What LMs Can Report About Their Own

https://arxiv.org/abs/2608.20569
1•sbulaev•6m ago•0 comments

Actually Queryable Executables

https://fzakaria.com/2026/08/24/actually-queryable-executables
1•ingve•7m ago•0 comments

DefCon 34 – Stalking the Wily Hacker: 40 years later – Cliff Stoll [video]

https://www.youtube.com/watch?v=656058JxTM0
2•ericd•15m ago•0 comments

Comparing the two holograms on the Windows 95 box

https://devblogs.microsoft.com/oldnewthing/20260824-00/?p=112643
1•st_goliath•17m ago•0 comments

Show HN: CookWing, an AI chef that doesn't hallucinate quantities

https://play.google.com/store/apps/details?id=com.redwing.vibecooking&hl=en_US
1•BananeDeRungis•20m ago•0 comments

Shazam.el

http://yummymelon.com/devnull/announcing-shazam-el.html
1•Tomte•20m ago•0 comments

Omarchy Exploit

https://www.youtube.com/watch?v=pgNvD9DaZxY
1•krehwell•22m ago•0 comments

Speculative Programmatic Tool Calling

https://alexzhang13.github.io/blog/2026/spec-ptc/
2•iamwil•25m ago•0 comments

Show HN: ShrinkRay – HandBrake for TinyML

https://github.com/TarulAhsan/ShrinkRay
1•EmonAhsan•27m ago•0 comments

Five spending categories absorbed 88% of the US middle fifth's raise (2013-2023)

https://efficientdollar.com/blog/leftover-money-after-essentials/
1•lundj•30m ago•0 comments

LLMPanel Deploy vLLM to RunPod or Vast.ai Without Kubernetes

https://llmpanel.io
1•SquidJack•32m ago•0 comments

Silence Is a Feature

https://aradar.top/posts/silence-is-a-feature/
3•aradar46•33m ago•0 comments

Beyond China's humanoid robots, a quieter machine revolution is unfolding

https://www.bbc.com/news/articles/c62m4zn1q6mo
2•nairteashop•34m ago•0 comments

National Police Union Blasts Flock CEO for Turning Against Police

https://ipvm.com/reports/union-who-flock
1•jhonovich•37m ago•0 comments

Artificial Intelligence Market (2026 – 2033)

https://www.grandviewresearch.com/industry-analysis/artificial-intelligence-ai-market
1•Rutujad•38m ago•0 comments

Show HN: Tmtail – Multi-log tail with coloring, search, and history via tmux

https://github.com/themadsens/tmtail
1•themadsens•42m ago•0 comments

Surge in AI-assisted complaints putting extra strain on councils and schools

https://www.bbc.co.uk/news/articles/c2dk6wzjw23o
2•tomwphillips•42m ago•0 comments

Avery–MacLeod–McCarty Experiment

https://en.wikipedia.org/wiki/Avery%E2%80%93MacLeod%E2%80%93McCarty_experiment
1•num42•43m ago•0 comments

Ukraine hands Britain 'goldmine' of secret battlefield intelligence

https://www.independent.co.uk/news/uk/home-news/ukraine-britain-battlefield-intelligence-russia-s...
2•Teever•46m ago•0 comments

Moral Realism

https://philosophy.unc.edu/wp-content/uploads/sites/122/2014/07/Moral-Realism.pdf
1•andsoitis•46m ago•0 comments

I made HACKER AI for you vibecoded app

https://www.netherite.uz
1•apexxx•46m ago•0 comments

Reality Realism

https://philarchive.org/archive/CARRRK
1•andsoitis•47m ago•0 comments

Singapure Unveils Biological Data Center Prototype

https://medicine.nus.edu.sg/news/nus-medicine-dayone-and-cortical-labs-unveil-biological-data-cen...
1•vasco•47m ago•0 comments

Logging in Was Never Supposed to Be This Complicated

https://www.theatlantic.com/technology/2026/08/password-manager-login-difficulty/688396/
2•littlexsparkee•57m ago•0 comments

Ask HN: Can token caching be a business idea?

1•sourav_biswas•1h ago•2 comments

The .NET One Person Framework

https://github.com/pal-tamas/rask
1•pal-tamas•1h ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.