frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Succession – Agent Lineage Evolution for an Agentic World

https://danieltan.weblog.lol/2026/04/succession-ale-for-an-agentic-world
1•danieltanfh95•3m ago•0 comments

Motorola USB OTG Problems (2023)

https://goughlui.com/2025/09/20/notes-motorola-moto-g84-5g-usb-otg-problems-bad-vbus/
1•goodburb•3m ago•0 comments

Gemini CLI accessed outside permited directory, then admits fault

https://twitter.com/i/status/2041317025583374376
1•yowayb•5m ago•1 comments

How Plausible Is 'Project Hail Mary'? Astrophysicists Have Thoughts

https://www.nytimes.com/2026/04/04/movies/project-hail-mary-scientific-accuracy.html
3•bookofjoe•8m ago•1 comments

Solod – A Subset of Go That Translates to C

https://github.com/solod-dev/solod
2•TheWiggles•10m ago•0 comments

Memory poisoning in AI coding agents

https://github.com/asamassekou10/ship-safe
1•asamassekou•11m ago•0 comments

Goodbye, middle managers. Hello, 'player-coaches' and 'org leads'

https://www.businessinsider.com/meta-block-managers-player-coaches-org-leads-2026-4
1•indigodaddy•15m ago•1 comments

Report: Apple has shifted 40% of planned MacBook production capacity to Vietnam

https://twitter.com/dnystedt/status/2041310255305642278
2•ilamont•26m ago•0 comments

Feynman: Open-source AI research agent

https://www.feynman.is/
1•m_kos•30m ago•0 comments

TraceFix – A simple tool to trace issues from logs faster

https://tracefix.vercel.app/
1•skillsettler•38m ago•1 comments

I made Claude slower and it changed how I use it

https://www.xda-developers.com/i-made-claude-slower-and-it-completely-changed-how-i-use-it/
1•NicoJuicy•43m ago•0 comments

Coexilia: Master Hash Manifest (v1.0)

https://archive.org/details/coexilia-master-hash-manifest-v-1.0
1•aegissolis•47m ago•0 comments

Analysis finds geometric thinking may come from wandering

https://phys.org/news/2026-04-analysis-geometric-human-math-module.html
2•pseudolus•49m ago•0 comments

You've Been Lied to About DNA Evidence [video]

https://www.youtube.com/watch?v=9okaPzpVhmM
1•gmays•49m ago•1 comments

The Hacker News Tarpit

https://www.joanwestenberg.com/the-hacker-news-tarpit/
4•sonicrocketman•50m ago•1 comments

Ask HN: Has your company implemented agentic coding?

2•ronbenton•51m ago•0 comments

Agentic memory: the field is converging – but we're measuring the wrong thing

1•liamsfr•52m ago•0 comments

Fujitsu One Compression

https://FujitsuResearch.github.io/OneCompression/
3•gmays•53m ago•0 comments

Show HN: Invariant – pre-execution control layer for agentic workflows

https://invariant.me
1•iq19zero•54m ago•0 comments

Show HN: Separating work and play in Claude Code

https://github.com/diranged/claude-profile
2•diranged•55m ago•0 comments

Goldman Sachs to laid-off tech workers: take time, earnings loss to find new job

https://finance.yahoo.com/news/goldman-sachs-blunt-warning-to-laid-off-tech-workers-it-will-take-...
5•pseudolus•55m ago•4 comments

NY Yankees' torpedo bat is the same as regular bat

https://news.wsu.edu/press-release/2026/04/02/science-confirms-torpedo-bat-works-as-well-as-regul...
3•geox•56m ago•0 comments

Show HN: Knowledge Bases for AI/Human Sharing

https://akuna.software/introduction
1•smissingham•56m ago•0 comments

High AI judgment consistency does not mean high reasoning quality (preprint)

https://zenodo.org/records/19446064
1•h_hasegawa•59m ago•0 comments

Hello World

https://apod.nasa.gov/apod/ap260404.html
2•beatthatflight•59m ago•1 comments

Show HN: Where Is Artemis? Realtime open source 3D tracker for Artemis 2 mission

https://where-is-artemis.com
1•mareko•1h ago•0 comments

OpenAI's vision for the AI economy: public wealth funds, robot taxes, and more

https://techcrunch.com/2026/04/06/openais-vision-for-the-ai-economy-public-wealth-funds-robot-tax...
2•evo_9•1h ago•0 comments

Factory Makes the Most Expensive Stuff [video]

https://www.youtube.com/watch?v=jjp3WC8Unj8
1•chilipepperhott•1h ago•0 comments

Show HN: Physical constants from 2 integers – MIT, 1225 tests, falsifiable

https://bpr.thestardrive.com
2•iq19zero•1h ago•0 comments

Sourcehut disrupted due to DDoS attack

https://status.sr.ht/issues/2026-04-06-ddos-attack/
1•0xsn3k•1h ago•0 comments