frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

When Trump Jawbones the Market, Bet Against Him at Your Peril

https://www.wsj.com/economy/when-trump-jawbones-the-market-bet-against-him-at-your-peril-92825a3e
1•petethomas•4m ago•0 comments

Show HN: TeardownHQ, teardowns/playbooks of how indie startups grew

https://teardownhq.io
2•arogers17•6m ago•0 comments

Barcelona's Sagrada Família Nears Completion–and Inflames a Tourism Backlash

https://www.wsj.com/world/europe/barcelonas-sagrada-familia-nears-completionand-inflames-a-touris...
1•petethomas•7m ago•0 comments

Jeff Bezos Is Funding a Wild Hunt for the Brain's 'Core Algorithm'

https://www.wired.com/story/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm/
1•uxhacker•14m ago•0 comments

Cremona Art Week

https://0100101110101101.org/show-cremona-art-week/
1•jruohonen•14m ago•0 comments

Israel says it has struck Iran after taking missile fire

https://apnews.com/article/iran-us-ceasefire-hezbollah-israel-c16dc4917512f7436a3921a4b044b98b
2•JumpCrisscross•18m ago•1 comments

Sunset of the Consumer Version of Gemini Code Assist on GitHub

https://developers.google.com/gemini-code-assist/docs/deprecations/consumer-code-review
1•tvvocold•25m ago•0 comments

The coming rise of anti-AI populism

https://www.ft.com/content/b4429ea0-4a0a-4a28-96f5-debf4f3eb339
1•1vuio0pswjnm7•25m ago•1 comments

A New Ad Campaign Tries to Make A.I. A Little Less Scary

https://www.nytimes.com/2026/06/04/style/chatgpt-advertising-campaign-artificial-intelligence.html
1•1vuio0pswjnm7•28m ago•1 comments

Painting the Internet: A Different Kind of Warhol Worm [pdf]

https://cspages.ucalgary.ca/~aycock/papers/artworm.pdf
1•jruohonen•33m ago•0 comments

Texas grid flags risks as data centers, crypto sites fail voltage tests

https://www.reuters.com/business/energy/texas-grid-flags-risks-data-centers-crypto-sites-fail-vol...
10•1vuio0pswjnm7•33m ago•0 comments

April in Servo: new Android UI, focus, forms, security fixes, and more

https://servo.org/blog/2026/05/31/april-in-servo/
1•maxloh•33m ago•0 comments

The source of economic shocks matters for their political outcomes

https://journals.sagepub.com/doi/10.1177/20531680251379914
4•PaulHoule•36m ago•0 comments

Tech sell-off widens as South Korea index plunges

https://www.ft.com/content/2f0f727b-5315-445c-b8f1-6aa65bd7474c
5•JumpCrisscross•37m ago•0 comments

Yoti denies reporting GrapheneOS user, says screenshots may be fake

https://discuss.grapheneos.org/d/36134-grapheneos-user-reported-to-authorities-for-using-graphene...
3•Cider9986•37m ago•1 comments

Earthquake of magnitude 7.8 strikes off southern Philippines

https://www.reuters.com/business/environment/earthquake-magnitude-73-strikes-mindanao-philippines...
1•JumpCrisscross•39m ago•1 comments

Algorithmic Monocultures in Hiring

https://algorithmichiring.github.io/
7•drchiu•43m ago•0 comments

NPM-Scan: Detecting Six Major NPM Supply Chain Campaigns (June 2026)

https://www.npmjs.com/package/@lateos/npm-scan
2•lateos-ai•46m ago•0 comments

Show HN: ARouter – drop-in OpenAI/Anthropic proxy that cuts cost and fails over

https://github.com/sricola/arouter
1•sricola•49m ago•1 comments

What it costs to run a one-Rails-app SaaS per month

https://www.railsreviews.com/articles/what-it-costs-to-run-a-rails-saas
2•doppp•54m ago•0 comments

President says Netanyahu will have 'no choice' but to accept a deal with Iran

https://www.ft.com/content/a0ce59f9-fbde-49e8-9158-fba3d4079859
2•Jimmc414•56m ago•1 comments

Force-sensing mobile microrobotic grippers for gentle and precise bioassembly

https://pubs.aip.org/aip/apb/article/10/2/026103/3388070/Force-sensing-mobile-microrobotic-grippe...
2•PaulHoule•56m ago•0 comments

New drug 'functionally cures' many hepatitis B virus infections

https://www.science.org/content/article/new-drug-functionally-cures-many-hepatitis-b-virus-infect...
12•gmays•57m ago•0 comments

Show HN: Preseason.ai – Open-source benchmark of devtool choices, ranked by LLM

https://www.preseason.ai
2•widenrun•58m ago•0 comments

DeepSeek V4 Pro beats GPT-5.5 Pro on precision

https://runtimewire.com/article/deepseek-v4-pro-beats-gpt-5-5-pro-on-precision
49•yogthos•59m ago•4 comments

Phonestheme

https://en.wikipedia.org/wiki/Phonestheme
3•davidbarker•1h ago•0 comments

Newborns' cry melody is shaped by their native language

https://pubmed.ncbi.nlm.nih.gov/19896378/
1•davidbarker•1h ago•0 comments

Dev log:Made an app blocker unlocks by verifying real App HealthKit data

https://disciplinelock.com/
1•zichengwang•1h ago•0 comments

1worldflag: A blue dot on a transparent background

https://1worldflag.com/
3•davidbarker•1h ago•0 comments

Attitudes toward same-sex marriage and transgender issues are shifting

https://apnews.com/article/gallup-poll-same-sex-marriage-morality-e12acb151446ac1b7970c0825bf1d072
2•petethomas•1h ago•1 comments