frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Chebyshev Polynomials and Their Derivatives in C

https://leetarxiv.substack.com/p/chebyshev-polynomials-are-ferraris
1•theanonymousone•11s ago•0 comments

Boot Naked Linux

https://nick.zoic.org/art/boot-naked-linux/
2•abnercoimbre•1m ago•0 comments

HTTPS: //webhook.site live testing of web hooks

https://webhook.site
2•janandonly•2m ago•0 comments

AI Slop Has Taken over LinkedIn

https://keegan.codes/blog/a-slop-has-taken-over-linkedin
2•mooreds•3m ago•0 comments

Show HN: Machine0 – Persistent NixOS VMs You Control from the CLI

https://machine0.io
2•bwm•3m ago•0 comments

GPT-5 Nano Vulnerability test results you should know before deploying

https://lateos.ai/llm-research/gpt5-nano/
2•lateos-ai•3m ago•0 comments

Show HN: An interactive Snake circuit you can take apart, no CPU

https://simten.dev/blog/snake-in-hardware
2•charlesfrisbee•3m ago•0 comments

Why Dragon Quest Has Always Been More Popular in Japan (2023)

https://www.denofgeek.com/games/dragon-quest-popularity-japan-explained/
2•mooreds•4m ago•0 comments

Verifiable Execution: Proving How Work Happened in Workflows and Agents

https://www.cncf.io/blog/2026/06/11/introducing-verifiable-execution-in-dapr-1-18/
2•yaronsc•4m ago•0 comments

Ficus Elastica

https://en.wikipedia.org/wiki/Ficus_elastica
2•mooreds•4m ago•0 comments

"I reverse engineered Verizon's VoWiFi and called from a laptop modem"

https://twitter.com/AliceInDisarray/status/2066417720292163960
2•ent101•4m ago•0 comments

Linux 7.0 Adds Support for BPF Filtering to IO_uring

https://www.phoronix.com/news/Linux-7.0-IO-uring-BPF-Filter
2•teleforce•5m ago•0 comments

Code a Database in 45 Steps

https://trialofcode.org/database/
2•firephox•9m ago•0 comments

AI GPUs probably live longer than three years

https://www.seangoedecke.com/ai-gpus-live-longer-than-three-years/
1•Brajeshwar•10m ago•0 comments

UK unveils social media ban for users under 16

https://techcrunch.com/2026/06/15/uk-unveils-sweeping-social-media-ban-for-users-under-16/
1•SilverElfin•12m ago•1 comments

Show HN: We put voice agent on our website, learned retrieval isn't bottleneck

https://www.moss.dev/blog/founding-agent
4•srimalireddi•12m ago•0 comments

Large Text Compression Benchmark

https://www.mattmahoney.net/dc/text.html
1•nathan-barry•13m ago•0 comments

Locus Founder from Locus (YC F25)

https://locusfounder.com/
2•wezabis•13m ago•0 comments

Britain Announces Social Media Ban for Children

https://www.nytimes.com/2026/06/15/world/europe/uk-social-media-children.html
1•1vuio0pswjnm7•14m ago•0 comments

AI Won't Fix a Company That Can't Ship

https://agileproductdevelopment.substack.com/p/ai-wont-fix-a-company-that-cant-ship
1•speckx•14m ago•0 comments

The Bright Side of ADHD: Dr. Ned Hallowell on Embracing and Succeeding with Add

https://additudemag.libsyn.com/the-bright-side-of-adhd-dr-ned-hallowell-on-embracing-and-succeedi...
1•yablak•15m ago•0 comments

Show HN: Continuous Nvidia CUDA PC Sampling Profiler

https://www.polarsignals.com/blog/posts/2026/06/10/nvidia-cuda-pc-sampling
2•gnurizen•15m ago•1 comments

SHOW HN: I created a Show HN social app where you can show your projects

https://kritive.com
1•sambhav10•16m ago•0 comments

Show HN: PDF Export YouTube Transcriptions

1•cristyg0101•17m ago•0 comments

Sand Bubbler Crab

https://en.wikipedia.org/wiki/Sand_bubbler_crab
1•thunderbong•19m ago•0 comments

Growing the Cloudflare AI Team with Talent from Ensemble AI

https://blog.cloudflare.com/ensemble-ai-talent-joins-cloudflare/
1•jgrahamc•19m ago•0 comments

Mythos-class models will diffuse throughout the world by 2029

https://spateder.com/projects/20260611/openweightmodels
1•gmays•19m ago•0 comments

Show HN: Prodgate, a CLI that catches Express auth regressions in PRs

https://github.com/prodgate-dev/prodgate
1•anans04•21m ago•0 comments

Othello World

https://flowtwo.io/post/othello-world
1•thomasjb•21m ago•0 comments

Show HN: Exploiting Slack's video embeds to achieve E2EE communication

https://v1c.rocks/log/exploiting-slack-video/
6•victorio•21m ago•0 comments