frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•11mo ago

Comments

kemotep•11mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

The Absolute Best Water Reactor

https://www.decouple.media/p/the-absolute-best-water-reactor
1•leonidasrup•43s ago•1 comments

Ancient Philosophy, in Plain English

https://thinkplain.ai/
1•thecosas•1m ago•0 comments

People Do Not Yearn for Automation

https://www.theverge.com/podcast/917029/software-brain-ai-backlash-databases-automation
2•icco•1m ago•0 comments

"Hot spots" for glyphosate and cancer in Iowa and other Midwest states

https://www.thenewlede.org/2026/03/analysis-find-hot-spots-for-glyphosate-and-cancer-in-iowa/
1•PaulHoule•1m ago•0 comments

SpaceX IPO filing shows Elon Musk can retain board control

https://www.reuters.com/sustainability/boards-policy-regulation/spacex-ipo-filing-shows-elon-musk...
1•1vuio0pswjnm7•2m ago•0 comments

'CAR' crash: Avis Budget stock plunge reminding some on Wall Street of GameStop

https://www.cnbc.com/2026/04/23/car-crash-avis-budget-stock-plunge-reminding-some-on-wall-street-...
1•paulpauper•3m ago•0 comments

macOS window internals: SkyLight enables multi-cursor background agents

https://github.com/trycua/cua/blob/main/blog/inside-macos-window-internals.md
1•frabonacci•3m ago•0 comments

Microsoft Offers Buyouts to 7% of Workforce

https://www.wsj.com/tech/microsoft-offers-buyouts-to-7-of-workforce-755b8534
2•ripvanwinkle•3m ago•1 comments

Another crash caused by uninstaller code injection into Explorer

https://devblogs.microsoft.com/oldnewthing/20260423-00/?p=112261
1•r4um•4m ago•0 comments

The Unusual Short Squeeze Behind Avis's Wild Rally

https://www.wsj.com/livecoverage/stock-market-today-dow-sp-500-nasdaq-04-22-2026/card/the-unusual...
1•paulpauper•4m ago•0 comments

Section 230 Defeats Discord's "Defective Design" Sex Predation Claims

https://blog.ericgoldman.org/archives/2026/04/section-230-helps-discord-defeat-defective-design-c...
1•01-_-•5m ago•0 comments

What Anthropic's Claude Mythos and My Divorce Have in Common

https://mythos.one/me/brianswichkow/00c227
1•brianswichkow•6m ago•0 comments

Palantir Employees Are Starting to Wonder If They're the Bad Guys

https://www.wired.com/story/palantir-employees-are-starting-to-wonder-if-theyre-the-bad-guys/
3•pavel_lishin•7m ago•0 comments

House Republicans roll out landmark data privacy push

https://www.politico.com/news/2026/04/22/house-republicans-roll-out-landmark-data-privacy-push-00...
3•1vuio0pswjnm7•8m ago•0 comments

Show HN: JustFYI – a paywall detector for "free" online tools

https://justfyi.app
1•vlad1m1r•8m ago•0 comments

Software stocks plunge on ServiceNow, IBM results as AI fears escalate

https://www.cnbc.com/2026/04/23/software-stocks-plunge-on-servicenow-ibm-results-ai-fears-escalat...
1•01-_-•8m ago•0 comments

Canonical Releases Ubuntu 26.04 LTS Resolute Raccoon

https://ubuntu.com/blog/canonical-releases-ubuntu-26-04-lts-resolute-raccoon
4•l2dy•12m ago•1 comments

Egyptian mummy discovered stuffed with excerpt from 'The Iliad'

https://www.popsci.com/science/egyptian-mummy-iliad/
3•Brajeshwar•13m ago•0 comments

A tiny world of friendly web pets

https://webpets-flame.vercel.app/
2•Liriel•13m ago•0 comments

Show HN: Python 0.9.1 from 1991, Guido van Rossum's first public release

https://github.com/tamnd/python-0.9.1
1•tamnd•13m ago•0 comments

Show HN: Ungate – use Claude and ChatGPT subscriptions in Cursor without tokens

https://github.com/orchidfiles/ungate
1•theorchid•14m ago•0 comments

Why Not Use Lean?

https://lawrencecpaulson.github.io//2026/04/23/Why_not_Lean.html
1•baruchel•16m ago•0 comments

Show HN: Rusty Browser – AI rust service spinning up AI browsers

1•ish099•16m ago•0 comments

New connectors in Claude for everyday life

https://claude.com/blog/connectors-for-everyday-life
1•louiereederson•16m ago•0 comments

A Full Apple Ecosystem Now Costs Less Than a MacBook Pro

https://www.macrumors.com/2026/04/23/apple-ecosystem-now-costs-less-than-macbook-pro/
3•thm•17m ago•0 comments

Modern cults are replacing leaders with 'life coaches'

https://english.elpais.com/society/2026-04-11/modern-cults-are-replacing-leaders-with-life-coache...
1•geox•18m ago•0 comments

Canonical Releases Ubuntu 26.04 LTS Resolute Raccoon

https://canonical.com/blog/canonical-releases-ubuntu-26-04-lts-resolute-raccoon
2•trojanowski•21m ago•0 comments

Why You Should Work at a Startup in 2026

https://dharmasamu.com/blog/why-work-at-a-startup-2026
2•dharmateja03•21m ago•1 comments

Ask HN: How much AI slop do you deal with at work?

1•conqrr•21m ago•1 comments

Agents with similar accuracy to Mythos claims do Apple MacBook M5/A18 pro audit

https://github.com/dmaynor/apple-vuln-research
1•dmaynor•22m ago•1 comments