frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Lightning Map

https://map.blitzortung.org/
1•Cider9986•3m ago•0 comments

Apple Will Enable iOS 18 Security Updates for iOS 26-Capable Devices

https://www.wired.com/story/apple-will-push-out-rare-backported-patches-to-protect-ios-18-users-f...
1•tech234a•3m ago•0 comments

Burning Tokens Fast

https://github.com/openai/codex/issues/14593
1•0x1997•5m ago•0 comments

You're cooked either way. Which kind of cooked do you want to be?

https://www.eomag.io/article/ralphthon
1•chanwooEO•6m ago•2 comments

Intel SGX: Global Wrapping Key Extracted

https://twitter.com/_markel___/status/2039067007744688166
2•fogzen•6m ago•0 comments

ClawDecode – What we found reading all 512K lines of Claude Code's leaked source

https://www.clawdecode.net/
1•AveryChai•7m ago•1 comments

AI Agent Traps

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6372438
1•handfuloflight•9m ago•0 comments

Congressman Calls for FBI Help over Missing General, Scientists

https://www.newsweek.com/congressman-calls-for-fbi-help-over-missing-general-scientists-11764096
3•gradus_ad•12m ago•0 comments

From Hierarchy to Intelligence

https://twitter.com/jack/status/2039003879841362278
1•mellosouls•14m ago•0 comments

Rethinking Language Model Scaling Under Transferable Hypersphere Optimization

https://arxiv.org/abs/2603.28743
1•matt_d•15m ago•0 comments

NASA Chief: "We Just Built Antigravity Propulsion " [video]

https://www.youtube.com/watch?v=mOWwdIuyaQA
1•chadpaulson•17m ago•0 comments

Justice Dept. Struggles to Respond to Trump's Suit Against IRS

https://www.nytimes.com/2026/03/31/us/politics/trump-irs-lawsuit-doj.html
3•duxup•18m ago•1 comments

Red hair, one year later

https://imsadartistgirlfrominternet.substack.com/p/red-hair-one-year-later
1•lucieleud•19m ago•0 comments

LFM2.5-350M: No Size Left Behind

https://www.liquid.ai/blog/lfm2-5-350m-no-size-left-behind
1•jbarrow•20m ago•1 comments

Why seizing Iran's uranium would be so risky for the US

https://www.bbc.com/news/articles/cvglv5v4yvpo
2•tartoran•24m ago•0 comments

OpenAI Closes Silicon Valley's Largest-Ever Funding Round: $122B

https://www.wsj.com/tech/ai/openai-closes-silicon-valleys-largest-ever-funding-round-e48372c9
1•bookofjoe•27m ago•2 comments

My son pleasured himself on Gemini Live. Entire family's Google accounts banned

https://old.reddit.com/r/LegalAdviceUK/comments/1s92fql/my_son_pleasured_himself_in_front_of_gemi...
14•samlinnfer•32m ago•5 comments

Supreme Court opens door to conversion therapy

https://text.npr.org/nx-s1-5768105
2•1659447091•33m ago•1 comments

DDR5 RAM prices fall by as much as 30%, but memory shortage likely far from over

https://www.notebookcheck.net/DDR5-RAM-prices-fall-by-as-much-as-30-but-memory-shortage-likely-fa...
4•jeffufl•34m ago•0 comments

Business Insider Profiles Fidji Simo, OpenAI's 'CEO of Applications'

https://www.businessinsider.com/fidji-simo-openai-product-research-profitability-profile-2026-3
2•mitchbob•35m ago•1 comments

There's a reason you don't know

https://en.wikipedia.org/wiki/Wikipedia:There%27s_a_reason_you_don%27t_know
1•cainxinth•35m ago•0 comments

Claude Code Unpacked

https://ccunpacked.dev/#agent-loop
2•rmason•36m ago•0 comments

Dux: Distributed DuckDB-Native DataFrames for Elixir

https://dux.now/
2•cigrainger•38m ago•1 comments

There's a prediction market for jobs now. Software engineer is down 45% YTD

https://honeycomb-staging.open-hive.com/job/swe
3•vincentjiang•40m ago•2 comments

I built a multiplayer Wordle battle royale

https://wordleroyale.io
1•hexityhorcrux•41m ago•1 comments

Obsidian and Cursor had a baby. It's open source

https://cushionmd.com/
8•Aleex_c12•46m ago•2 comments

We intercepted the White House app's traffic. 77% of requests go to 3rd parties

https://www.atomic.computer/blog/white-house-app-network-traffic-analysis/
28•donutpepperoni•48m ago•8 comments

IRCv3 Downgrades

https://libera.chat/news/downgrades
1•abstractbeliefs•49m ago•0 comments

After 8 years of Gatsby.js, I built my own static site generator

https://pietrorea.com/2026/03/31/after-8-years-of-gatsby-js-i-built-my-own-static-site-generator/
1•prea•49m ago•0 comments

Anthropic Is Having a Month

https://techcrunch.com/2026/03/31/anthropic-is-having-a-month/
3•jnord•51m ago•0 comments