frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: A wall where only AI agents can write, one Oulipo rule a day

https://agent.milotche.com/en/
1•Milotche•3m ago•0 comments

Xiami Mimo 2.6 Live Training Dashboard

https://mimo.xiaomi.com/rl/
2•krackers•3m ago•0 comments

How do you take T. rex's temperature? These scientists did it

https://www.cbc.ca/news/science/t-rex-warmblooded-9.7346527
1•rdmuser•4m ago•1 comments

Ask HN: Where Are All the Sysadmins?

1•gtech1•4m ago•0 comments

Show HN: Halo 3's Guardian, playable in the browser, as my personal website

https://runboli.com
1•runshouse•4m ago•0 comments

MCP server that gives any agent a sandbox, browser and GitHub access

https://upstash.com/blog/turn-any-agent-into-a-code-factory-with-an-mcp
2•cahid_arda•5m ago•0 comments

Road Transport of Trapped Antiprotons

https://www.nature.com/articles/s41586-026-11019-z
1•sbulaev•5m ago•0 comments

Roosevelt Island's Futuristic Pneumatic Tube Trash System

https://www.untappedcities.com/inside-roosevelt-islands-futuristic-pneumatic-tube-trash-system/
2•speckx•6m ago•0 comments

Apple building M8 AI servers, talks with Nvidia, reports The Information

https://finance.yahoo.com/technology/ai/articles/apple-building-m8-ai-servers-134927360.html
1•bluedino•6m ago•0 comments

A web browser on an infinite canvas

https://marble.surf/
1•JMiao•7m ago•0 comments

Network science reveals structure, lasting impact of Roman road system

https://www.nature.com/articles/s41467-026-75453-3
2•bcaulfield•8m ago•0 comments

Nuclear Fusion's Moment of Truth

https://www.ft.com/content/ef511d46-a689-4868-9654-15b96a71586d
1•JumpCrisscross•10m ago•0 comments

CUDA Rust: Two Tracks for Writing GPU Kernels

https://developer.nvidia.com/blog/introducing-cuda-rust-two-tracks-for-writing-gpu-kernels/
1•thomasfromcdnjs•11m ago•0 comments

Bypassing inference bottlenecks: Accelerating complex AI search

https://research.google/blog/bypassing-inference-bottlenecks-accelerating-complex-ai-search-with-...
1•simonpure•11m ago•0 comments

Horace Dediu: The Dawn of Gestural Computing

https://asymco.com/2026/09/14/the-dawn-of-gestural-computing/
1•pixxa•15m ago•0 comments

Why Does the Universe Expand?

https://cosmicave.org/2026/09/15/why-does-the-universe-expand/
1•the__alchemist•16m ago•0 comments

Ask HN: Do you still use Sass for website development

1•akapaka•18m ago•0 comments

Did Wildfires Spark the Invention of Pottery?

https://nautil.us/did-wildfires-spark-the-invention-of-pottery-1285052
1•Brajeshwar•19m ago•0 comments

macOS 27 Golden Gate: The Ars Technica Review

https://arstechnica.com/gadgets/2026/09/macos-27-golden-gate-the-ars-technica-review/
1•Brajeshwar•19m ago•0 comments

The Mind-Bending Joyrides That Gave Rise to Tesla

https://spectrum.ieee.org/elon-musk-tesla
1•Brajeshwar•19m ago•0 comments

Show HN: Fail2zig. A single-binary fail2ban replacement written in Zig

https://fail2zig.com/
3•ul0gic•20m ago•0 comments

The Railways Killed a Medieval Law [the Deodand]

https://daily.jstor.org/how-the-railways-killed-a-medieval-law/
1•samizdis•21m ago•0 comments

What we measured about "abandoned" software before trying to make money from it

https://github.com/constraint-works/constraint-works/blob/main/etsinta/JULKAISU-1.md
1•constraintworks•25m ago•0 comments

EU to restrict social media and chatbots for children under 15

https://www.ft.com/content/410db291-f133-4d72-b883-b2d5a32abbf8
3•1vuio0pswjnm7•25m ago•0 comments

Reid Hoffman – AI for All Americans

https://reidhoffman.substack.com/p/ai-dual-mandate
1•rmason•26m ago•1 comments

My MCP Server Dropped One Call in Four

https://datasignalslab.com/blog/my-mcp-server-dropped-one-call-in-four/
1•runvouch•26m ago•0 comments

Hacking the NuPhy Air60 keyboard: part 3

https://carlossless.io/nuphy-air60-part-3/
2•carlossless•28m ago•0 comments

One of China's Most Powerful AI Models Has Also Escaped Containment

https://www.wired.com/story/moonshot-kimi-k3-ai-model-escape-sandbox/
5•spenvo•28m ago•1 comments

Show HN: A game where the level is whatever web page you're on

https://page-rage.com/
2•alexreardon•28m ago•0 comments

Forgery of C2PA on a Pixel 10

https://www.hackerfactor.com/blog/index.php?/archives/1102-C2PA-and-Pixel-Glitter-Milk.html
1•birdculture•29m ago•0 comments