frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•7mo ago

Comments

kemotep•7mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Yann LeCun Is Raising Half a Billion Dollars to Build Nothing (Yet)

https://medium.com/@anwarzaid76/yann-lecun-is-raising-half-a-billion-dollars-to-build-nothing-yet...
1•MindBreaker2605•52s ago•0 comments

Show HN: No Fun Allowed

https://josevalerio.com/no-fun-allowed
1•josevalerio•4m ago•0 comments

Show HN: Zimage2.online – An AI image tool built on Alibaba's Z-Image model

https://zimage2.online/
1•chenliang001•6m ago•0 comments

The ML Trench

https://deep-ml-trench.vercel.app/
1•hexhowells•7m ago•0 comments

The iPhone 16e Is Good

https://manualdousuario.net/en/iphone-16e-is-good-actually/
1•rpgbr•8m ago•0 comments

AI in 2026 and beyond ⊗ Bioregionalism's tech-driven revival

https://sentiers.media/ai-in-2026-and-beyond-bioregionalisms-tech-driven-revival-no-384/
1•speckx•8m ago•0 comments

Show HN: Dots: a bullet journal I built to understand my migraines

https://dotsjournal.app/
1•tubignaaso•10m ago•0 comments

US submarines are outnumbered in the Pacific. South Korea has a plan to help

https://www.cnn.com/2025/12/20/asia/south-korea-nuclear-powered-submarines-intl-hnk-ml-dst
1•breve•10m ago•0 comments

Construct in 2025: Year in Review

https://www.construct.net/en/blogs/construct-official-blog-1/construct-2025-year-review-1898
1•AshleysBrain•15m ago•0 comments

Teardown of the Gigaset CL660HX DECT phone and how to disable annoying flash LED

https://github.com/hn/gigaset-cl660hx
1•hn___•16m ago•0 comments

New mathematical framework reshapes debate over simulation hypothesis

https://www.santafe.edu/news-center/news/new-mathematical-framework-reshapes-debate-over-simulati...
2•Gooblebrai•16m ago•0 comments

Show HN: Pilotbook.pro – born from spending more time on paperwork than flying

https://pilotbook.pro/
1•j4nitor•17m ago•0 comments

A Knapsack Public Key Cryptosystem Based on Arithmetic in Finite Fields (1988) [pdf]

https://people.csail.mit.edu/rivest/pubs/CR88.pdf
1•keepamovin•20m ago•0 comments

Google Cloud Infrastructure 2025: The Year Kubernetes Got Boring

https://www.aimeemarieknight.com/Google-Cloud-Infrastructure-2025-The-Year-Kubernetes-Got-Boring/
1•speckx•20m ago•0 comments

Use Claude Code with OpenRouter

https://openrouter.ai/docs/guides/guides/claude-code-integration
2•Topfi•22m ago•0 comments

Show HN: Mntn v2.0 – CLI for system maintenance, backups, and dotfile management

https://github.com/alexandretrotel/mntn
1•alexandretrotel•22m ago•0 comments

Grappling with its worst drought in a century, Iraq bets on oil-for-water deal

https://www.cnn.com/2025/12/21/climate/iraqs-oil-water-turkey-intl-latam
1•breve•24m ago•0 comments

ISBN Visualization Showing 99_959_000 books

https://annas-archive.li/isbn-visualization/
10•simon04•28m ago•1 comments

How to not end up in a Louis Rossmann video

https://sschueller.github.io/posts/how-to-not-end-up-in-a-louis-rossmann-video/
1•sschueller•31m ago•0 comments

Org Social surpassed twtxt in activity

https://preview.org-social.org/?post=https%3A%2F%2Fhost.org-social.org%2Fandros%2Fsocial.org%2320...
1•andros•32m ago•0 comments

Practical Tips for Cheating at Design (2018)

https://medium.com/refactoring-ui/7-practical-tips-for-cheating-at-design-40c736799886
1•Tomte•35m ago•0 comments

Techniques in Persuasion from Antiquity (2023)

https://www.thecollector.com/persuasive-technques-antiquity/
1•Tomte•35m ago•0 comments

The Infinite Software Crisis – Jake Nations, Netflix [video]

https://www.youtube.com/watch?v=eIoohUmYpGI
1•ceyhunkazel•36m ago•0 comments

Darktable 5.4 Released

https://www.darktable.org/2025/12/darktable-5.4.0-released/
3•Derbasti•38m ago•0 comments

Standard Chartered halves BTC USD 2025 target and pushes $500K goal to 2030

https://economictimes.indiatimes.com/news/international/us/bitcoin-price-forecast-cut-to-100k-why...
1•janandonly•40m ago•0 comments

Show HN: I built an LLM agent that finds you online and roasts you

https://santa.veris.ai
2•_josh_meyer_•41m ago•0 comments

The QuickShot II Joystick Returns [video]

https://www.youtube.com/watch?v=IaUU4Es4dGU
1•doener•42m ago•0 comments

Unix Fourth Edition

http://squoze.net/UNIX/v4/README
2•naves•43m ago•0 comments

Show HN: OpenHands-AAAA

https://codeberg.org/erkinalp/OpenHands-AAAA
1•anticensor•44m ago•1 comments

Show HN: GoRay – Ray Core for Golang

https://github.com/ray4go/go-ray
2•Wang0618•44m ago•0 comments