frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Detecting scraper bots through scroll behaviour

https://niki.cat/detecting-scraper-bots-through-scroll-behaviour
1•theanonymousone•2m ago•0 comments

US power grid at risk of 18-month blackout; 1 city now in dark for over a week

https://www.syracuse.com/us-news/2026/08/us-power-grid-at-risk-of-18-month-blackout-1-city-now-in...
3•newsomix9xl•3m ago•0 comments

Frank Beard, ZZ Top drummer for more than five decades, dies at 77

https://www.theguardian.com/music/2026/aug/20/frank-beard-obituary
1•bookofjoe•7m ago•0 comments

OpenAI Unveils Zero Data Retention for Frontier Models

https://techstrong.ai/articles/openai-unveils-zero-data-retention-for-frontier-models-previews-pr...
1•CrankyBear•8m ago•0 comments

Slack Datamine

https://github.com/3kh0/slack-datamine
1•sadeshmukh•9m ago•0 comments

The Jagged GTM Frontier

https://freshcontext.ai/research/jagged-gtm-frontier
2•bcx•10m ago•0 comments

How to Not Burnout

https://alikhil.dev/posts/how-to-not-burnout/
1•alikhil•11m ago•0 comments

Dissecting the "Beginning Analysis" of Noncitizen Voting

https://mdi.georgetown.edu/response-to-voter-record-analysis/
2•Anon84•12m ago•0 comments

We knew game hardware spending would drop, July's percentages are still shocking

https://www.destructoid.com/gaming-hardware-decline-sales/
1•evo_9•12m ago•0 comments

Show HN: Lexicon – Vocabulary That Sticks

https://lexiconapp.pythonanywhere.com/
1•chistev•16m ago•1 comments

Remove Cruft from Amazon

https://shop.knockoff.co
2•sanj•19m ago•0 comments

Show HN: Hackerznews – Yet Another HN Client

https://hackerznews.vercel.app
1•raphael_l•25m ago•0 comments

Is AI spend on OpenAI or Anthropic starting to eat into your runway?

https://rails-agent.com/
1•kannanreghu•27m ago•0 comments

Embedded Swift Improvements Coming in Swift 6.4

https://swift.org/blog/embedded-swift-improvements-coming-in-swift-6.4/
1•frizlab•28m ago•0 comments

OpenAI's Unreleased Model Astra Solves Ten Major Open Mathematics Problems

https://thezvi.substack.com/p/openais-unreleased-model-astra-solves
1•paulpauper•28m ago•0 comments

Nicotine: It Works

https://www.technotheoria.org/p/nicotine-it-works
2•paulpauper•29m ago•0 comments

Omaha school district asks police to stop using shock gloves on students

https://apnews.com/article/shock-gloves-omaha-school-district-police-9f73e909eb5c4e948632eb28ea56...
2•petethomas•29m ago•0 comments

Results from the Backblaze Generative AI Media Hackathon

https://www.backblaze.com/blog/results-from-the-backblaze-generative-ai-media-hackathon/
1•roan-we•29m ago•0 comments

Glycogen storage capacity and denovo lipogenesis during carbohydrate overfeeding [pdf]

https://paulogentil.com/pdf/Glycogen%20storage%20capacity%20and%20de%20novo%20lipogenesis%20durin...
1•paulpauper•30m ago•0 comments

Hosted a Public Muscriptor Instance (latest, most powerful Audio-to-MIDI model)

https://muscriptor-iota.vercel.app/
1•jardy•31m ago•0 comments

Show HN: Aristra, your life OS

https://aristralabs.com
1•player08•31m ago•0 comments

Why the Future of AI Belongs to Systems That Can Self-Learn

https://medium.com/@vektormemory/the-case-for-agent-memory-why-the-future-of-ai-belongs-to-system...
1•vektormemory•33m ago•0 comments

Why I Quit the Tenure Track: The insufferable hypocrisy of elite academia

https://www.theatlantic.com/magazine/2026/09/elite-academia-leadership-hypocrisy/687969/
3•zahlman•33m ago•0 comments

Macpackages.com a small tool to know what's installed and running on your macOS

https://macpackages.com/
1•akmarco•35m ago•0 comments

Show HN: Zero () friction local AI for Mac

https://www.basecompute.co/local
2•lukasonedge•37m ago•0 comments

Show HN: Youtilitics, energy usage analytics from utility data, no hardware

https://youtilitics.com/
2•ClaudyFocan•37m ago•0 comments

Network-flow ML that outputs security incidents

https://github.com/ibondarenko1/security-anomaly-ml
1•ibondarenko1•38m ago•0 comments

AIs Are Not People

https://rogueresearch.substack.com/p/ais-are-not-people
2•measurablefunc•41m ago•0 comments

The domain name fluid.sh is for sale

https://fluid.sh
1•zahrevsky•42m ago•1 comments

Trump hid in catering truck in secret plane swap over Iran threat

https://www.bbc.com/news/articles/cm2g90vvy62o
5•gmays•43m ago•1 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.