frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Where Does the Tone Come from in a Microphone Preamp? [video]

https://www.youtube.com/watch?v=K-vIeA7yy6Q
1•BrokenCogs•32s ago•0 comments

Ask HN: It's World Social Media Day. Which current ones you do and don't enjoy?

1•busymom0•57s ago•0 comments

The mise en abyme in the Drowned World by James G. Ballard [pdf]

https://dialnet.unirioja.es/descarga/articulo/10247620.pdf
1•jruohonen•1m ago•0 comments

Codegrain – browser-based PDF/image/data tools, files never leave your tab

https://private-tools.codegrain.dev/en
1•shaidiuk•1m ago•0 comments

So, did Dolly from 'Moonraker' wear braces or not?

https://old.reddit.com/r/skeptic/comments/1uhwkh4/so_did_dolly_from_moonraker_wear_braces_or_not/
1•Teever•2m ago•0 comments

./the-bored-engineer –episode=1

https://github.com/quantumwake/kas
1•boredengineer•3m ago•0 comments

Booz Allen: What's in America's Code? Testing U.S. and Chinese LLMs for Security

https://www.boozallen.com/expertise/cybersecurity/whats-in-americas-code.html
1•jlark77777•4m ago•0 comments

Anonymous researcher drops 0-day 'exploitarium' repo

https://www.theregister.com/security/2026/06/29/anonymous-researcher-drops-0-day-exploitarium-rep...
1•logickkk1•4m ago•0 comments

Supreme Court strikes down executive order ending birthright citizenship

https://www.scotusblog.com/2026/06/supreme-court-strikes-down-trumps-order-ending-birthright-citi...
1•hallole•4m ago•0 comments

Show HN: Don't ask if devs cheat with AI, test if they're good with it

https://tryevaluator.com
2•skyepstein•8m ago•1 comments

The Origin of Continents and Geology's Theory of Everything

https://worksinprogress.co/issue/on-the-origin-of-continents/
1•duffycommaryan•9m ago•0 comments

Scammers Sell Seeds for Exotic AI-Generated Flowers That Don't Exist

https://www.404media.co/scammers-sell-seeds-for-exotic-ai-generated-flowers-that-dont-exist/
3•Brajeshwar•9m ago•0 comments

Show HN: Let your AI agent manage your link in bio

https://keepp.link/keepp-skill/SKILL.md
1•vasanthps•9m ago•0 comments

The Beauty of Tautologies

https://scottsumner.substack.com/p/the-beauty-of-tautologies
1•surprisetalk•9m ago•1 comments

Show HN: FastReact – FastAPI and React Starter Kit for AI SaaS

https://fastreact.dev/
1•turtledevio•10m ago•0 comments

Claude Code Is Steganographically Marking Requests

https://thereallo.dev/blog/claude-code-prompt-steganography
3•kirushik•10m ago•0 comments

OSS Rust Web framework inspired by Nest.js

https://rustnidus.com/
1•Vicbona•11m ago•0 comments

Why don't tech workers see themselves as workers?

https://techwerkers.nl/en/posts/myth-of-middle-class/
2•lowbar•12m ago•2 comments

We encode time in space, and pay in complexity

https://notes.shixiangxi.com/en/docs/dual-world-theory/preface/
2•sxx0•12m ago•1 comments

The Cantillion Effect – Adam Smith Institute

https://www.adamsmith.org/blog/the-cantillion-effect
2•bilsbie•15m ago•0 comments

Everything Easy is Hard Again (2018)

https://frankchimero.com/blog/2018/everything-easy/
3•downbad_•15m ago•1 comments

Samsung, SK Hynix to Spend $520B on Chip Plants in South Korea

https://www.wsj.com/tech/samsung-sk-hynix-to-spend-520-billion-on-chip-plants-in-south-korea-7d50...
2•mushstory•15m ago•0 comments

Benchmarks and Obscurantism: A "red" line that should not be crossed

https://clickhouse.com/blog/databricks-reyden-benchmark-transparency-clickhouse
1•lightningspirit•16m ago•0 comments

LLM KOSH

https://github.com/rastogivaibhav/llm-kosh
1•rastogivaibhav•16m ago•0 comments

VSCode-pull-request-GitHub repeatedly asked to sign in again using GitHub

https://github.com/microsoft/vscode-pull-request-github/issues/8786
1•Klaster_1•19m ago•0 comments

No Systemd

https://nosystemd.org/
2•standeven•19m ago•0 comments

The labor share of income in the US is at its lowest post-war level

https://libertystreeteconomics.newyorkfed.org/2026/06/the-post-covid-decline-in-the-labor-share/
99•loughnane•19m ago•21 comments

Study Reveals How Leukemia Cells Enter and Damage Lungs

https://nyulangone.org/news/study-reveals-how-leukemia-cells-enter-and-damage-lungs
3•gmays•20m ago•0 comments

Supreme Court strikes down limits on party spending in federal elections

https://apnews.com/article/supreme-court-campaign-finance-party-spending-ohio-91e49ee112197ae1210...
3•khriss•20m ago•1 comments

Agents in Orbs

https://ampcode.com/news/agents-in-orbs
2•tosh•21m ago•0 comments