frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

A Minimal Python Reimplementation of Claude Code

https://pypi.org/project/patchpal/
1•wiseprobe•1m ago•0 comments

But What About Greenland? – Wait but Why (2014)

https://waitbutwhy.com/2014/09/but-what-about-greenland.html
1•mefengl•3m ago•0 comments

Ask HN: Would you use AI-personalized newsletters?

https://www.upletter.app/
1•josevalencar•3m ago•1 comments

AI Coding Agents Hallucinate – Real-Time ResearchAgent

https://hallucinationtracker.com
1•amadosalsta•5m ago•0 comments

Autopsy reveals Daniel Naroditsky's probable cause of death

https://www.charlotteobserver.com/news/local/article314402626.html
1•amrrs•7m ago•0 comments

Attitude-based networking

https://vece.ai/compare-yourself
1•iliakoliev•12m ago•1 comments

Tiny Mars Has a Big Impact on Our Climate

https://nautil.us/tiny-mars-has-a-big-impact-on-our-climate-1262470/
1•Bender•15m ago•0 comments

The Heat Pump relay race

https://www.heatpumped.org/p/the-heat-pump-relay-race
1•ssuds•17m ago•0 comments

Probing quantum mechanics with nanoparticle matter-wave interferometry

https://www.nature.com/articles/s41586-025-09917-9
1•cpncrunch•17m ago•0 comments

Threat Actors Expand Abuse of Microsoft Visual Studio Code

https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code/
3•vinnyglennon•17m ago•0 comments

AMD launches 34GB AI bundle in latest driver update

https://www.pcguide.com/news/amd-launches-massive-34gb-ai-bundle-in-latest-driver-update-heres-wh...
1•kristianp•20m ago•0 comments

Making activities load 500x faster than the most popular feed

https://getfast.ai/blogs/activity-feed
3•steadyelk•21m ago•0 comments

Personalized travel itineraries, mapped and shareable

https://TryTourify.app
1•Arnoldsaurus•24m ago•0 comments

Show HN: Dotenv Mask Editor: No more embarrassing screen leaks of your .env

https://marketplace.visualstudio.com/items?itemName=xinbenlv.dotenv-mask-editor
1•xinbenlv•24m ago•0 comments

Doctors raise alarm over declining vaccine rates in America's most vulnerable

https://www.dailymail.co.uk/health/article-15484717/doctors-warn-declining-vaccine-rate-older-adu...
4•Bender•26m ago•1 comments

Ask HN: Have your views about AI / LLMs changed? What triggered it?

3•ATechGuy•26m ago•0 comments

From Stealth Blackout to Whitelisting: Inside the Iranian Shutdown

https://www.kentik.com/blog/from-stealth-blackout-to-whitelisting-inside-the-iranian-shutdown/
1•oavioklein•28m ago•0 comments

Clawdbot Showed Me What the Future of Personal AI Assistants Looks Like

https://www.macstories.net/stories/clawdbot-showed-me-what-the-future-of-personal-ai-assistants-l...
1•janpio•29m ago•0 comments

1 in 35,385 US immigrants are in MN+criminal+undocumented

3•QuantumGood•29m ago•1 comments

Taboo against harming strangler fig spirits protects forests in Borneo

https://news.mongabay.com/2025/12/taboo-against-harming-strangler-fig-spirits-protects-forests-in...
2•PaulHoule•31m ago•0 comments

Fixes That Made My Website Faster and More Accessible

https://dingyu.me/blog/7-fixes-that-made-my-website-faster-and-more-accessible
1•felixding•32m ago•0 comments

Google Cloud to shut down Memorystore for Memcached by Jan 2029

https://docs.cloud.google.com/memorystore/docs/memcached/deprecation/memcached
2•tokkyokky•32m ago•1 comments

Starlight, a Bitcoin-native platform for turning ideas into funded work

https://starlight-ai.freemyip.com/
1•macroadster•33m ago•1 comments

Spend Decisions Get Approved

https://www.letsriff.ai/blog/from-emails-and-excel-to-decision-clarity-fixing-how-spend-decisions...
1•wheresclark•33m ago•0 comments

Lix – universal version control system for binary files

https://lix.dev/blog/introducing-lix/
4•onecommit•34m ago•0 comments

Wasma – Windows Assignment System Monitoring Architecture

https://github.com/Azencorporation/Wasma
1•goychay23•38m ago•1 comments

Show HN: PolyMCP – open-source toolkit to expose MCP tools and run agents

1•justvugg•38m ago•0 comments

Ark and GENESIS A protocol for sovereign know nodes and consent-based federation

1•PiSounds•38m ago•0 comments

On Mark Carney's use of "The Power of the Powerless" at the WEF

https://twitter.com/SilviaPencak/status/2013705975207797113
2•nailer•39m ago•0 comments

New Linux Patch Improved NVMe Performance And15% with CPU Cluster-Aware Handling

https://www.phoronix.com/news/Faster-Linux-NVMe-Cluster-Aware
2•Bender•39m ago•0 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.