frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Sovereign AI: Why Owning the Full Stack Is the New Strategic Imperative

https://www.forbes.com/sites/chuckbrooks/2026/04/22/sovereign-ai-why-owning-the-full-stack-is-the...
1•zzzeek•29s ago•0 comments

One Year with Codeberg

https://guix.gnu.org/blog/2026/one-year-with-codeberg//
2•iamnothere•52s ago•0 comments

OpenAI Codex has a bug that could kill your SSD in under a year

https://www.notebookcheck.net/OpenAI-Codex-has-a-bug-that-could-kill-your-SSD-in-under-a-year.132...
2•abixb•1m ago•0 comments

Canada is looking to build up to 10 new nuclear reactors over the next 15 years

https://www.cbc.ca/news/politics/federal-nuclear-strategy-9.7244509
2•geox•6m ago•0 comments

Ratchets Run Faster with Resharp

https://danverbraganza.com/writings/ratchets-run-faster-with-resharp
1•nvader•6m ago•0 comments

FFmpegKit, revived – a maintained Android build after the original was retired

https://github.com/ffmpegkit-maintained/ffmpeg-kit
1•FFmpegKit•6m ago•0 comments

The art of the swarm: Systemic rivalry with China on European terms

https://ecfr.eu/publication/the-art-of-the-swarm-systemic-rivalry-with-china-on-european-terms/
1•simonebrunozzi•7m ago•0 comments

Memory crisis is getting so bad that even retro RAM prices are going to the Moon

https://www.theregister.com/personal-tech/2026/06/22/the-memory-crisis-is-getting-so-bad-that-eve...
1•speckx•8m ago•0 comments

A self-hosted auditor that tells you if your portfolio thesis still holds

https://daniwave313.gumroad.com/l/tlghil
1•dgomloz•8m ago•0 comments

Paradise Revisited: What Darwin Saw in the Galápagos

https://www.theatlantic.com/magazine/2026/08/writers-way-galapagos-charles-darwin-travel/687480/
2•lbeckman314•13m ago•1 comments

Blobly

https://blobly.medv.io/
2•medv•14m ago•0 comments

Kafka's Broken Promise: There Is No Goldilocks Log

https://www.opendata.dev/blog/announcing-opendata-log/
4•apurvamehta•15m ago•0 comments

Show HN: Making a new video game every day with Claude (Day 69: Hot Death Zero)

https://freepocketgames.com/69-hot-death-zero
1•pzxc•16m ago•0 comments

Ask HN: How to manage AI spam in inbox?

1•bmau5•16m ago•0 comments

Company Brain – Open-Source

https://github.com/KubaKoobz/sotu-copilot
1•kuba87•17m ago•0 comments

Doorbell cam filmed Tesla Autopilot crash that killed woman in her home

https://arstechnica.com/tech-policy/2026/06/woman-killed-when-tesla-driver-using-autopilot-crashe...
1•speckx•18m ago•0 comments

Little Alchemy 2

https://www.crazygames.com/game/little-alchemy-2
2•thunderbong•20m ago•0 comments

A Dark Dimension Could Link Two of the Universe's Great Unknowns

https://www.quantamagazine.org/a-dark-dimension-could-link-two-of-the-universes-great-unknowns-20...
1•pavel_lishin•20m ago•0 comments

Steam Machine – Valve's living-room PC, take two [video]

https://www.youtube.com/watch?v=Fi7n9fYQelA
1•coolwulf•21m ago•0 comments

Could lightning-inspired fertilizer be climate-friendly for Canadian farmers?

https://www.cbc.ca/radio/whatonearth/green-lightning-climate-friendly-fertilizer-canadian-farmers...
1•LostMyLogin•21m ago•0 comments

Patch the Planet: a Daybreak initiative to support open source maintainers

https://openai.com/index/patch-the-planet/
1•conslit•22m ago•0 comments

Gorilla: Large Language Model Connected with APIs

https://gorilla.cs.berkeley.edu/
1•gmays•22m ago•0 comments

Offrrd – Your AI job-search coach

https://offrrd.com
1•mbjjr•23m ago•0 comments

Canada just lowered a 953-tonne slab of steel and concrete into a 35-meter shaft

https://www.autonocion.com/us/canada-tonne-grid-nuclear-reactor/
1•PaulHoule•24m ago•0 comments

Ask HN: Switching from backend development to graphics programming

1•laladrik•24m ago•0 comments

Qbit, a post-quantum UTXO testnet looking for technical review

https://qbit.org
4•vikmech•25m ago•1 comments

The chances of you living 50 years are very small

https://www.livescience.com/space/cosmology/the-chances-of-you-living-50-years-are-very-small-the...
1•bookofjoe•26m ago•0 comments

Unpacking sandbox startup latency: why started ≠ ready

https://modal.com/blog/unpacking-sandbox-startup-latency
1•heygarrison•28m ago•0 comments

Hackers sent fake alien invasion alerts to millions of Brazilians

https://dev.ua/en/news/feikovi-spovishchennia-pro-vtorhnennia-inoplanetian-1782139294
2•austinallegro•29m ago•0 comments

Doom64KB

https://github.com/FrenkelS/Doom64KB
1•wicket•31m ago•0 comments