frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Go CLI tool for AWS S3 security verification

https://github.com/sufield/stave
1•sufield•26s ago•0 comments

The AI bubble isn't new – Marx explained the mechanisms behind it 150 years ago

https://theconversation.com/the-ai-bubble-isnt-new-karl-marx-explained-the-mechanisms-behind-it-n...
1•vrganj•2m ago•0 comments

What to expect from the fiery, 14-minute return of Artemis II

https://arstechnica.com/space/2026/04/heres-what-to-expect-from-the-fiery-14-minute-return-of-art...
1•trothamel•2m ago•0 comments

Comparison Shopping Is Not a (Computer) Crime

https://www.eff.org/deeplinks/2026/04/comparison-shopping-not-computer-crime
1•hn_acker•2m ago•0 comments

Logic of Self vs. Logic of Role (and Why Confusing the Two Is a Trap)

https://www.leadingsapiens.com/logic-of-self-vs-logic-of-role/
1•sherilm•3m ago•0 comments

Cohn's "Privacy's Defender"

https://pluralistic.net/2026/04/09/bernstein-2/
1•hn_acker•4m ago•0 comments

But What about K?

https://tony-zorman.com/posts/whitney-k.html
1•mpweiher•4m ago•0 comments

UMR: Save LLM model disk space

https://github.com/EvanZhouDev/umr
1•thatxliner•5m ago•0 comments

Show HN: Kubbo – build a medieval city with your daily habits

https://kubbo.app/
1•macfleid•7m ago•0 comments

Let's Talk about LLMs

https://www.b-list.org/weblog/2026/apr/09/llms/
1•mpweiher•7m ago•0 comments

Explaining the Failures of Obesity Therapy

https://www.nature.com/articles/ijo2012114
1•paulpauper•8m ago•0 comments

Claude Mythos Is Everyone's Problem

https://www.theatlantic.com/technology/2026/04/claude-mythos-hacking/686746/
2•paulpauper•9m ago•1 comments

Not all index scans are equal: How we cut query latency by over 99%

https://www.datadoghq.com/blog/detect-inefficient-index-scans-with-dbm/
1•tanelpoder•9m ago•0 comments

Finding your investment lodestar: In search of an investment philosophy

https://aswathdamodaran.substack.com/p/finding-your-investment-lodestar
1•paulpauper•9m ago•0 comments

CIA to embed AI «co-workers» in every analytic platform within two years

https://anonhaven.com/en/news/cia-ai-coworkers-ellis-scsp-april-2026/
3•anonhaven•10m ago•0 comments

NASA's Dragonfly mission will send a nuclear-powered flying drone to Titan

https://www.scientificamerican.com/article/nasas-dragonfly-mission-will-send-a-nuclear-powered-fl...
1•Brajeshwar•10m ago•0 comments

Show HN: Wealth Curve – Financial forecasting with local storage and E2EE

https://wealthcurve.app/
1•fishbone•15m ago•0 comments

Show HN: IBANforge – Free IBAN/BIC validation API with compliance data

https://github.com/cammac-creator/ibanforge
1•Xentyon•15m ago•0 comments

Supply chain nightmare: How Rust will be attacked and what we can do to mitigate

https://kerkour.com/rust-supply-chain-nightmare
3•fanf2•16m ago•0 comments

Chewy to Acquire Modern Animal, Membership-Based Pet Healthcare Platform

https://investor.chewy.com/news-and-events/news/news-details/2026/Chewy-to-Acquire-Modern-Animal-...
2•randycupertino•17m ago•1 comments

Monarch: An API to Your Supercomputer

https://pytorch.org/blog/monarch-an-api-to-your-supercomputer/
1•gmays•18m ago•0 comments

CPU-Z and HWMonitor Compromised

https://old.reddit.com/r/pcmasterrace/comments/1sh4e5l/warning_hwmonitor_163_download_on_the_offi...
20•Wingy•21m ago•1 comments

Show HN: Agents that do the work and show it – kern

https://kern-ai.com/?release=v0.25.0
2•obilgic•22m ago•0 comments

Why do we tell ourselves scary stories about AI?

https://www.quantamagazine.org/why-do-we-tell-ourselves-scary-stories-about-ai-20260410/
9•lschueller•23m ago•5 comments

Bluesky users are mastering the fine art of blaming everything on "vibe coding"

https://arstechnica.com/ai/2026/04/bluesky-users-are-mastering-the-fine-art-of-blaming-everything...
7•ulrischa•23m ago•0 comments

Show HN: I wrote a practical guide to DSPy after 2 years of production use

https://harmlessdspy.com
1•aliirz•23m ago•0 comments

Design and Implementation of DuckDB Internals Course

https://github.com/DBatUTuebingen/DiDi
2•tanelpoder•24m ago•0 comments

How Germany is betting on international students amid demographic shift

https://thepienews.com/how-germany-is-betting-on-international-students-amid-demographic-shift/
1•rustoo•24m ago•0 comments

LibreOffice on the Brink: How the Document Foundation Shut Out Its Own Founders

https://forum.linuxguides.de/core/index.php?article/54-libreoffice-am-abgrund-wie-die-document-fo...
3•cachius•25m ago•1 comments

Nearly half of US data centers planned for 2026 canceled or delayed

https://www.msn.com/en-us/money/economy/nearly-half-of-us-data-centers-planned-for-2026-canceled-...
4•vrganj•26m ago•0 comments