frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

SpaceX offers details on orbital data center satellites

https://spacenews.com/spacex-offers-details-on-orbital-data-center-satellites/
1•MrBuddyCasino•1m ago•0 comments

Show HN: I created an app to copy OTP from Google Voice to your macOS Clipboard

https://github.com/ptrinh/Notiful
1•ptrinh•7m ago•0 comments

iPhone almost like a birth control device, fertility rates falling after 2007

https://www.indiatoday.in/technology/news/story/iphone-almost-like-a-birth-control-device-fertili...
1•rustoo•9m ago•0 comments

Ask HN: Do you need go-to-market strategy at early stage?

1•2ero_wf•13m ago•0 comments

Built to benefit everyone: our plan By Sam Altman and Jakub Pachocki

https://openai.com/index/built-to-benefit-everyone-our-plan/
1•echan00•17m ago•1 comments

Show HN: Clawcall – give your self-hosted OpenClaw agent inbound phone calls

https://github.com/CODEANDTRUST/clawcall
1•pakbry•19m ago•0 comments

L'Affaire Siloxane

https://mceglowski.substack.com/p/laffaire-siloxane
1•idlewords•19m ago•0 comments

Make Something Wonderful

https://joshuawold.com/make-something-wonderful/
1•ethanplant•26m ago•0 comments

Vulnerability and malware checks in UV: uv audit, malware check in uv add, sync

https://astral.sh/blog/uv-audit
3•Terretta•29m ago•1 comments

OxyJen v0.5: a deterministic graph runtime for AI workflows

https://github.com/11divyansh/OxyJen
1•bdivyansh11•30m ago•0 comments

The Capability Curve Has No Memory

https://medium.com/@vektormemory/the-capability-curve-has-no-memory-7c5fe5cde09f
1•vektormemory•34m ago•1 comments

ThumbLoop: Thumbnails Which Get Clicks

https://loop-tube.com/blog/how-to-make-youtube-thumbnails
1•yashness•36m ago•0 comments

Apple Investors Give Lukewarm Reaction to New Siri, AI Platform

https://www.bloomberg.com/news/articles/2026-06-08/apple-unveils-next-generation-of-ai-platform-i...
1•petethomas•41m ago•0 comments

Gram Newton-Schulz: A Fast, Hardware-Aware Newton-Schulz Algorithm for Muon

https://tridao.me/blog/2026/gram-newton-schulz/
2•jxmorris12•42m ago•0 comments

Siri AI at WWDC 2026

https://simonwillison.net/2026/Jun/8/wwdc/
2•lumpa•49m ago•0 comments

I built a free car lease transfer marketplace after the paid ones burned me

https://www.trademylease.com
2•mknweb•52m ago•0 comments

CRDTs merge concurrent edits. Why not concurrent creation?

https://loro.dev/blog/mergeable-containers
2•czx111331•53m ago•0 comments

OpenLTM – Local, self-decaying memory for AI coding agents

https://github.com/RohiRIK/OpenLtm
2•RohiRik•1h ago•0 comments

What Apple Knows About AI That Silicon Valley Won't Admit

https://www.thealgorithmicbridge.com/p/what-apple-knows-about-ai-that-silicon
5•CharlesW•1h ago•3 comments

Kalshi and Polymarket crack down on paid influencers claiming election fraud

https://text.npr.org/nx-s1-5846806
4•1659447091•1h ago•1 comments

Designing an AI-Native Technical Screen

https://i0exception.substack.com/p/designing-an-ai-native-technical
1•i0exception•1h ago•0 comments

They Have yet to Sign a Lease. But They're Furious over $3,100 Rents

https://www.nytimes.com/2026/06/07/nyregion/housing-costs-young-people-nyc.html
1•littlexsparkee•1h ago•0 comments

AI Coding Agent Platform

https://app.nz/
1•jacobianhessian•1h ago•0 comments

Show HN: Built an open-source local firewall for AI coding agents

2•ashishp15•1h ago•0 comments

NPM-Scan v1.4.1: Detecting IronWorm, Miasma Escalated, and Dependency Confusion

https://www.npmjs.com/package/@lateos/npm-scan
1•lateos-ai•1h ago•0 comments

Queues Don't Fix Overload (2014)

https://ferd.ca/queues-don-t-fix-overload.html
1•locknitpicker•1h ago•0 comments

Universal XSS in Firefox Focus for iOS

https://github.com/v12-security/pocs/tree/main/firefox
4•ledoge•1h ago•0 comments

Organizations Drift into Politics: A Follow-up to Game Theory Patterns at Work

https://daeus.blog/2026/06/08/how-organizations-drift-into-politics/
4•kurinikku•1h ago•0 comments

Gordon S. Wood dies at 92 after being hit by a car

https://www.nytimes.com/2026/06/08/books/gordon-s-wood-dead.html
6•2510c39011c5•1h ago•1 comments

Porting the ThinkPad X61 to Coreboot

https://blog.aheymans.xyz/post/thinkpad_x61/
5•walterbell•1h ago•0 comments