frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

The Problem Is Prompt Debt

https://www.dbreunig.com/2026/06/22/the-problem-is-prompt-debt.html
1•ingve•28s ago•0 comments

What data on myself I collect and why? (2020)

https://beepb00p.xyz/my-data.html
1•downbad_•42s ago•0 comments

Agents Are the New Product's Interface

https://www.hopsworks.ai/post/agents-are-your-new-product-interface
1•LexSiga•1m ago•0 comments

Ranked: Countries Spending the Most on Research and Development

https://www.visualcapitalist.com/ranked-countries-spending-most-on-r-and-d/
1•theanonymousone•5m ago•0 comments

Smart Hotel Management Software for Hotels, Resorts and Vacation Rentals

https://app.notion.com/p/Smart-Hotel-Management-Software-for-Hotels-Resorts-Vacation-Rentals-de44...
1•jackarnold•8m ago•0 comments

"Start with a Monolith" Was Good Advice. AI Is Changing That

https://medium.com/@pivotfakie/start-with-a-monolith-was-good-advice-ai-is-changing-that-a2181b8e...
1•feeblefakie•9m ago•0 comments

How to Apply Google's Open Knowledge Format (OKF) on Enterprise Level

https://community.obsidian.md/plugins/vault-operator
1•pssah4•11m ago•1 comments

Full Metal Jacket. Copper Edition – Vollebak

https://vollebak.com/en-us/products/full-metal-jacket-copper-edition
1•evo_9•12m ago•0 comments

OpenAI Codex bombards SSDs with needless write operations, costing millions

https://www.theregister.com/ai-and-ml/2026/06/23/openai-codex-bombards-ssds-with-needless-write-o...
1•jonbaer•14m ago•0 comments

The Digital Sovereignty Trap

https://statedept.substack.com/p/the-digital-sovereignty-trap
1•ryzvonusef•16m ago•0 comments

PixelSmash – FFmpeg's MagicYUV decoder vuln leads to RCE via media file

https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/
1•n0on3•16m ago•0 comments

AI Steps Off the Screen

https://epics.tech/posts/2026-06-23-ai-steps-off-the-screen/
2•epicsagas•18m ago•0 comments

Benchmark object storage in objects/s, not GB/s

https://fractalbits.com/blog/objects-per-second/
7•zzsheng•28m ago•0 comments

Dietary guidelines do not yield sufficient flavanol for cardiovascular benefit

https://pubs.rsc.org/en/content/articlehtml/2026/fo/d6fo00867d
2•littlexsparkee•29m ago•0 comments

AxLLM

https://axllm.dev/
2•handfuloflight•31m ago•0 comments

RIP Fable

https://fable.rip
2•opndragoon•34m ago•0 comments

Lucid to lay off roughly 18% of U.S. workforce, COO Marc Winterhoff leaves

https://www.cnbc.com/2026/06/22/lucid-layoffs-evs.html
2•mgh2•40m ago•0 comments

Clean sweep for Mamdani-backed candidates in New York's Democratic primary

https://www.bbc.com/news/articles/clye652m41po
2•mikhael•49m ago•0 comments

2026 vs. 1996 Chevrolet Blazer IIHS crash test

https://www.youtube.com/watch?v=4U8Ero-3GxI
3•plun9•51m ago•2 comments

VoltanaLLM: Energy-Efficient LLM Serving

https://supercomputing-system-ai-lab.github.io/projects/voltana/
2•matt_d•53m ago•0 comments

2003-era DDR2 memory prices jump up to 60%

https://www.tomshardware.com/pc-components/dram/ddr2-memory-prices-jump-up-to-60-percent
2•pkaeding•54m ago•1 comments

Sakana Fugu Technical Report

https://www.chapterpal.com/s/7ff4f6ba/sakana-fugu-technical-report
1•theanonymousone•54m ago•1 comments

Show HN: Deploy to Vercel, Netlify, Railway, Render, Cloudflare in 1 Command

https://xiaohou2503687-design.github.io/shipfast-oss/
1•shipfastai•54m ago•0 comments

Intel shareholder sues to void deal giving U.S. gov $11B in stock for free

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6985440
4•de6u99er•58m ago•1 comments

Sakana Fugu Ultra promises to deliver "the best frontier-level performance"

https://www.theverge.com/ai-artificial-intelligence/953904/sakana-fugu-ai
1•theanonymousone•1h ago•1 comments

TSMC: 36.1 A 32Gb/s 10.5Tb/s/mm 0.6pJ/b UCIe-Compliant Low-Latency Interface 3nm

https://ieeexplore.ieee.org/document/10904767
3•Alien1Being•1h ago•0 comments

Trump Gets Negative Reviews Internationally as Fewer Say US Is Reliable Partner

https://www.pewresearch.org/global/2026/06/23/trump-gets-negative-reviews-internationally-as-fewe...
4•Bondi_Blue•1h ago•0 comments

OpenAI spending hit $34B last year ahead of planned IPO

https://www.ft.com/content/e15b0d7e-ff6b-4f16-ba7a-4068feddb828
2•1vuio0pswjnm7•1h ago•1 comments

The Junior Developer Problem Is Becoming a Senior Developer Problem

https://www.vincentschmalbach.com/the-junior-developer-problem-is-becoming-a-senior-developer-pro...
4•vincent_s•1h ago•0 comments

Show HN: Fork.ai – branch any AI answer into a mind map instead of a chat log

https://forkai.in
1•gokulmc•1h ago•0 comments