frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: NowThis – OSS task manager for Nextcloud and iOS supporting subtasks

https://nowthis.app/
1•andrewjneumann•58s ago•0 comments

The Submarine

https://www.paulgraham.com/submarine.html
1•bilsbie•3m ago•0 comments

SkyPilot Endpoints: Production-Ready Inference on Every Cluster You Own

https://blog.skypilot.co/skypilot-endpoints/
1•rombr•3m ago•0 comments

The Hotness Curve (how age changes a woman's appeal)

https://aella.substack.com/p/the-hotness-curve-how-age-changes
1•SLHamlet•5m ago•0 comments

My Pele Agent Trading the World Cup Prediction Markets with AI and Crypto

https://avc.xyz/my-pele-agent
1•rmason•8m ago•0 comments

Claude Skill that turns the 37signals decision guide into a thinking partner

https://github.com/FeroVolar/Decision-Framework-Skill/
2•alianinfo•9m ago•1 comments

Field Note #009: The Asymmetric Exposure

https://www.azimuth.so/p/field-note-009-the-asymmetric-exposure
2•bennieblanco•13m ago•0 comments

Anthropic Accuses Alibaba of 'Illicitly' Accessing AI Models

https://www.bloomberg.com/news/articles/2026-06-24/anthropic-accuses-alibaba-of-illicitly-accessi...
4•htrp•15m ago•0 comments

Discovery of pneumonia subtypes could lead to tailored treatments

https://www.cam.ac.uk/research/news/discovery-of-severe-pneumonia-subtypes-could-lead-to-tailored...
2•gmays•16m ago•0 comments

Stop Programming in Markdown

https://structural.chat/articles/programming-in-markdown/
2•pchiusano•17m ago•0 comments

FilenQ – a native macOS file manager for power users

https://filenq.app
2•webseidon•19m ago•0 comments

RBX Insider

https://rbxinsider.net
2•fefw•19m ago•0 comments

Arcade Supports EMA

https://www.arcade.dev/blog/arcade-supports-ema/
2•gnanagurusrgs•20m ago•0 comments

Why SELECT * is bad for SQL performance (2020)

https://tanelpoder.com/posts/reasons-why-select-star-is-bad-for-sql-performance/
2•downbad_•20m ago•0 comments

Lost Confidence

https://longform.asmartbear.com/confidence/
2•herbertl•22m ago•0 comments

Benefit Is Not Authority

https://instantial.substack.com/p/benefit-is-not-authority
2•groverbennett•22m ago•0 comments

GitHub shouldn't be a dependency for publishing Rust on crates.io

https://infosec.exchange/@mttaggart/116806641273303255
6•speckx•22m ago•0 comments

Stanford graduates rethink their futures as AI transforms tech

https://www.bbc.com/news/articles/c872j82j2qyo
4•jethronethro•23m ago•0 comments

You can see T-Mobile's acquisitions by where its logins are hosted

https://neobotnet.com/blog/cotw-t-mobile
2•caffeinedoom•23m ago•2 comments

50% of LG and Samsung smart TV apps embed residential proxies

https://cyberinsider.com/50-of-lg-and-samsung-smart-tv-apps-embed-residential-proxies/
8•Cider9986•25m ago•2 comments

Reliability Is an Enforcement Problem

https://instantial.substack.com/p/reliability-is-an-enforcement-problem
2•groverbennett•26m ago•0 comments

Slate Auto's simple electric truck starts at $24,950

https://techcrunch.com/2026/06/24/slate-autos-radically-simple-electric-truck-starts-at-24950/
2•tjwds•29m ago•1 comments

Claude Shannon: A Mathematical Theory of Cryptography

https://evervault.com/papers/shannon
2•ShaneCurran•31m ago•0 comments

Elon Musk denies Tesla's Autopilot caused crash that killed grandmother

https://arstechnica.com/tech-policy/2026/06/elon-musk-denies-teslas-autopilot-caused-crash-that-k...
3•worik•31m ago•2 comments

AI IQ Bio

https://www.aiiq.org/bio/
2•shea256•33m ago•0 comments

WebKit in Safari 27 Beta

https://webkit.org/blog/17967/news-from-wwdc26-webkit-in-safari-27-beta/
3•SllX•33m ago•0 comments

Find an open source alternative to anything

https://opensource.builders/
2•momentmaker•34m ago•0 comments

Meta pauses employee tracker for AI training amid privacy concerns

https://www.theguardian.com/technology/2026/jun/24/meta-pauses-employee-tracker-for-ai-training-a...
2•iamflimflam1•34m ago•1 comments

WikiHouse is a modular system for high performance, zero-carbon buildings

https://www.wikihouse.cc
2•momentmaker•36m ago•0 comments

A startup claims it broke through a bottleneck that's holding back LLMs

https://www.technologyreview.com/2026/06/19/1139313/a-startup-claims-it-broke-through-a-bottlenec...
3•theanonymousone•38m ago•0 comments