frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: Arxitect – Agentic Plugin for Architecture and Design Patterns

https://github.com/andonimichael/arxitect
1•iamandoni•1m ago•0 comments

Colorado's New Speed Camera System Makes Waze Nearly Useless

https://www.motor1.com/news/792050/colorado-automated-speed-limit-cameras/
1•c420•1m ago•0 comments

War crimes are no longer shameful. That should terrify you

https://www.aljazeera.com/opinions/2026/4/3/war-crimes-are-no-longer-shameful-that-should-terrify...
3•akyuu•3m ago•0 comments

Chip-scale optical wireless system hits 362 Gbps at half the energy of Wi-Fi

https://www.spiedigitallibrary.org/journals/advanced-photonics-nexus/volume-5/issue-02/026018/Chi...
2•prabal97•4m ago•0 comments

Bid to name a street in San Francisco

https://paintastreet.com/auction
1•akalin•5m ago•0 comments

Breaking Down the Cerebras Wafer Scale Engine

https://wafer.substack.com/p/breaking-down-the-cerebras-wafer
1•matt_d•7m ago•0 comments

Why Artemis 2 is going to the moon – and what NASA hopes to find

https://www.telegraph.co.uk/news/2026/04/02/nasa-hopes-secret-to-life-on-earth-on-dark-side-of-moon/
1•Stratoscope•7m ago•1 comments

Show HN: Simple Audio Sweeper

https://github.com/PJDude/sas
1•pjdude•8m ago•0 comments

Artemis II crew take 'spectacular' image of Earth

https://www.bbc.com/news/articles/ce8jzr423p9o
1•andsoitis•8m ago•1 comments

JSONata Comes to ColdFusion: Query and Transform JSON Like a Pro

https://www.mycfml.com/articles/jsonata-comes-to-coldfusion-query-and-transform-json-like-a-pro/
1•rmason•11m ago•0 comments

Show HN: A memory layer for AI agents that organizes itself

2•srisanth_temprl•12m ago•0 comments

Fun with CSF firmware RK3588 GPU firmware

https://thepixelspulse.com/posts/fun-with-csf-firmware-rk3588-gpu-firmware/
1•mfilion•13m ago•0 comments

The need for better compiler frontend benchmarks: Carbon's benchmarking approach

https://discourse.llvm.org/t/the-need-for-better-frontend-benchmarks/90257
1•matt_d•13m ago•0 comments

Do All Languages Cost the Same? Tokenization in the Era of Commercial LLMs

https://arxiv.org/abs/2305.13707
1•Anon84•14m ago•0 comments

Metal Gear Solid V – Graphics Study

https://www.adriancourreges.com/blog/2017/12/15/mgs-v-graphics-study/
3•aggrrrh•15m ago•0 comments

PIGuard: Prompt Injection Guardrail via Mitigating Overdefense for Free

https://injecguard.github.io/
3•mettamage•17m ago•0 comments

People born and raised in Germany without citizenship

https://anastasiiaiurshina.substack.com/p/the-ones-who-grew-up-inside-the-border
1•iurshina•17m ago•0 comments

I built an Xkcd #936-style passphrase generator

https://www.passwds.me
2•badmonday•17m ago•2 comments

The most contagious mental illness: Developing immunity to ideaology

https://stevebearman.substack.com/p/the-most-contagious-mental-illness
1•kabuks•18m ago•0 comments

Russian cosmism, the older brother of Nick Land's accelerationism, transhumanism

https://en.wikipedia.org/wiki/Russian_cosmism
3•random3•20m ago•0 comments

Malicious Packages Targeting Strapi Plugin Ecosystem Being Actively Published

https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/
1•birdculture•21m ago•0 comments

Casio|the Special One – S100X Japanese Lacquer Edition

https://www.casio.com/jp/basic-calculators/premium/en-s100x-jc1-u/
2•anonymouscaller•25m ago•0 comments

A Case for Procrastination

https://elijahpotter.dev/articles/a-case-for-procrastination
1•chilipepperhott•25m ago•0 comments

Hermes Agent by Nous Research

https://hermes-agent.nousresearch.com
3•tomaskafka•25m ago•0 comments

Five Trends that will Shape Urban Africa in 2026

https://thisweekinafrica.substack.com/p/five-trends-that-will-shape-urban-3a7
1•paulpauper•25m ago•0 comments

Age Verification on Systemd and Flatpak

https://cybrkyd.com/post/age-verification-on-systemd-and-flatpak/
17•londonanon•26m ago•8 comments

Lisette – Rust syntax, Go runtime

https://lisette.run/
1•jitl•26m ago•0 comments

VPS/VM

https://en.wikipedia.org/wiki/VPS/VM
2•bilegeek•26m ago•0 comments

Can A.I. Be Pro-Worker?

https://www.newyorker.com/news/the-financial-page/can-ai-be-pro-worker
1•paulpauper•26m ago•0 comments

Author of 'Why Nations Fail' warns U.S. democracy won't survive AI job-pocalypse

https://fortune.com/2026/02/22/who-is-daron-acemoglu-nobel-laureate-ai-job-layoffs-economic-inequ...
7•paulpauper•27m ago•0 comments