frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: Linux Journey for iOS

https://apps.apple.com/us/app/linux-journey/id6770861660
1•huhuhang•2m ago•0 comments

SpaceX Vow to Loft 1M AI Satellites Could Spark Doomsday Dive

https://www.forbes.com/sites/kevinholdenplatt/2026/05/31/spacex-vow-to-loft-1-million-ai-satellit...
1•paulpauper•8m ago•0 comments

Show HN: Memex – A local-first AI journal that keeps everything as Markdown

https://github.com/memex-lab/memex
1•sparkleMing•9m ago•0 comments

Diffusion over Networks

https://camerongordon0.substack.com/p/diffusion-over-networks
1•iciac•13m ago•0 comments

Anthropic is conditioning our minds

2•ms_menardi•13m ago•1 comments

The true reason C++ always wins [video]

https://www.youtube.com/watch?v=I7fEsbksKRE
1•AareyBaba•14m ago•0 comments

CVE-2026-31525: Linux Kernel Privilege Escalation Flaw

https://www.sentinelone.com/vulnerability-database/cve-2026-31525/
1•Wingy•17m ago•0 comments

U.S. Midterms Have a Cyber Problem, but It's Not at the Ballot Box

https://blog.checkpoint.com/exposure-management/the-2026-u-s-midterms-have-a-cyber-problem-but-it...
7•gnabgib•28m ago•2 comments

Show HN: LeetCode EasyRepeat – Anki for LeetCode

https://github.com/yc1838/LeetCode-EasyRepeat
1•yc1838•29m ago•0 comments

I Got $4.84 from a Class Action and They Didn't Want Me to Have It

https://labnotes.org/i-got-4-84-from-a-class-action-settlement-and-they-really-really-didnt-want-...
3•speckx•29m ago•0 comments

Election interlopers register 5K+ domains, hope to catch some voting phish

https://www.theregister.com/security/2026/06/01/5k-election-domains-registered-ahead-of-us-midter...
2•Bender•34m ago•1 comments

X.org Server Starts June Nine New Security Vulnerabilities Discovered via AI

https://www.phoronix.com/news/X.Org-9-Vulnerabilities-AI
1•Bender•34m ago•0 comments

Texas adds another solar farm as ERCOT grid demand soars

https://electrek.co/2026/06/01/texas-adds-another-huge-solar-farm-ercot-grid-demand-soars/
4•Bender•37m ago•0 comments

TLDR – Summarize paragraphs in real-time through Firefox

https://github.com/chudweiser/TLDR
1•chudweiser•40m ago•0 comments

Why Study CS? Thoughts on LLM-assisted software engineering

https://kmicinski.com/claude-code-and-why-study-cs
3•jruohonen•46m ago•0 comments

Anthropic and the caravel problem

https://radval.me/articles/anthropic-and-the-caravel-problem
2•rad_val•49m ago•1 comments

Why are audio front ends still optimized for CPUs? (MelT)

https://arxiv.org/abs/2606.01009
2•augustocamargo•51m ago•0 comments

Experts sound alarm over Elon Musk's 'coup' that's 'about to rob your 401k'

https://www.rawstory.com/elon-musk-2676979515/
14•xbmcuser•55m ago•1 comments

Shfl

https://shuffle.com?r=OWbDsJFjR1
2•conheohaiyen•55m ago•1 comments

Show HN: Transposify–change Spotify song key from your menubar for singing

https://github.com/evanhu1/transposify
2•evanhu_•1h ago•0 comments

Angry devs vow to flee GitHub Copilot as metered billing takes hold

https://www.theregister.com/ai-and-ml/2026/06/02/github-copilot-users-threaten-exit-as-metered-bi...
6•jay_kyburz•1h ago•2 comments

Neuropixels Opto: combining high-resolution electrophysiology and optogenetics

https://www.nature.com/articles/s41592-026-03076-z
3•bookofjoe•1h ago•0 comments

How to Optimize a CUDA Matmul Kernel for cuBLAS-Like Performance: A Worklog

https://siboehm.com/articles/22/CUDA-MMM
1•Areibman•1h ago•0 comments

Starbucks retired its AI agent just months after deployment

https://finance.yahoo.com/sectors/technology/articles/starbucks-quietly-retired-ai-agent-19225909...
1•cdrnsf•1h ago•2 comments

Show HN: Playing with genomics foundation models | Tutorial/Explainer article

https://dillondesilva.substack.com/p/playing-with-genomics-foundation
1•dillondesilva•1h ago•0 comments

More Time to Think

https://ma.ttias.be/more-time-to-think/
2•nreece•1h ago•0 comments

macOS needs its grid back

https://blog.hopefullyuseful.com/blog/macos-needs-its-grid-back/
52•ranebo•1h ago•24 comments

Interop 2026: Continuing to improve the web for developers

https://web.dev/blog/interop-2026
2•Topfi•1h ago•0 comments

Miasma supply chain attack: malicious code found in RedHat-cloud-services NPM

https://snyk.io/blog/miasma-supply-chain-attack-malicious-code-redhat-cloud-services-npm-packages/
1•jruohonen•1h ago•0 comments

Crystal Nights (2008)

https://www.gregegan.net/MISC/CRYSTAL/Crystal.html
9•rorylawless•1h ago•0 comments