frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•8mo ago

Comments

kemotep•8mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Keeping a suspense file gives you superpowers (2024)

https://pluralistic.net/2024/10/26/one-weird-trick/#todo
1•thunderbong•1m ago•0 comments

Commandments of LLM Use

https://www.mostlylucid.net/blog/graphrag-minimum-viable-implementation
1•haraldooo•3m ago•0 comments

The Physics of Dissonance and Harmony

https://www.youtube.com/watch?v=tCsl6ZcY9ag
1•fanf2•5m ago•0 comments

Show HN: Doculearn – How much of your Gen-AI code do you understand?

https://doculearnapp.com
1•williamai_•8m ago•0 comments

Show HN: One Minute News: Your Minimalist Anti-Clickbait News Platform

https://oneminutenews.org/
1•zfoong•8m ago•0 comments

The power of box dimension attacks on the Epstein files

2•fusionlove•9m ago•0 comments

How to Annotate Everything (2019)

https://beepb00p.xyz/annotating.html
1•Tomte•13m ago•0 comments

Cloudflare Is Ruining the Internet

https://www.slashgeek.net/2016/05/17/cloudflare-is-ruining-the-internet-for-me/
2•nomilk•13m ago•0 comments

Training intensity distribution of marathon runners across performance levels

https://researchprofiles.herts.ac.uk/en/publications/the-training-intensity-distribution-of-marat...
1•DyslexicAtheist•17m ago•1 comments

Eise.app – Easy (Planetary) Image Stacker in the Browser for Astrophotography

https://eise.app/
1•grgergo•30m ago•0 comments

AIChat: All-in-One LLM CLI Tool

https://github.com/sigoden/aichat
1•modinfo•36m ago•0 comments

Pilot reports UFO hovering beside jet, leaving air traffic control stunned

https://www.foxnews.com/us/pilot-reports-ufo-hovering-beside-jet-leaving-air-traffic-control-stun...
3•sipofwater•36m ago•1 comments

39C3: Power Cycles Streaming

https://streaming.media.ccc.de/39c3
1•sschueller•37m ago•0 comments

Does it help to know history? (2014)

https://www.newyorker.com/news/daily-comment/help-know-history
1•thinkingemote•40m ago•0 comments

Stimulant medications affect arousal and reward, not attention networks

https://www.cell.com/cell/fulltext/S0092-8674(25)01373-X
3•e-khadem•47m ago•0 comments

Show HN: A daily newsletter tool with an evergreen fallback queue

https://anntho.com
2•thepramodgeorge•50m ago•0 comments

I don't do GitHub pull requests – Linus Torvalds

https://github.com/torvalds/linux/pull/17
5•Fiveplus•50m ago•1 comments

Alternative Christmas Message

https://en.wikipedia.org/wiki/Alternative_Christmas_message
1•dataflow•50m ago•0 comments

QNX Self-Hosted Developer Desktop Brings QNX 8.0 to a Wayland and XFCE Desktop

https://www.phoronix.com/news/QNX-Self-Hosted-Dev-Desktop
3•todsacerdoti•51m ago•0 comments

Ask HN: Does my "Narrative Fix" service solve a problem for Technical Founders?

1•JGgrowth•51m ago•0 comments

52 years later, only known copy of Unix v4 recovered from randomly found tape

https://www.tomshardware.com/software/linux/unix-v4-recovered-from-randomly-found-tape-at-univers...
2•aihash•52m ago•0 comments

Notepad-like simple text editor where files are saved and encrypted with AES-256

https://github.com/ivoras/EncryptedNotepad2
2•taubek•52m ago•0 comments

Show HN: Ez FFmpeg – Video editing in plain English

http://npmjs.com/package/ezff
34•josharsh•1h ago•9 comments

Verdichtung

https://alexeygy.github.io/blog/verdichtung/
1•kenty•1h ago•0 comments

Charlie Mackesy's Rules for Life

https://www.newstatesman.com/culture/books/2025/12/charlie-mackesy-and-the-illusion-of-control
1•thinkingemote•1h ago•0 comments

Our king, our priest, our feudal lord; how AI is taking us back to the dark ages

https://www.theguardian.com/commentisfree/2025/dec/26/ai-dark-ages-enlightenment
2•Brajeshwar•1h ago•0 comments

Cross-platform client mod for Slack desktop

https://github.com/jeremy46231/taut
2•sadeshmukh•1h ago•0 comments

No gels, no foams: Catalonia turns to grannies to teach traditional cooking

https://www.theguardian.com/world/2025/dec/27/grannies-catalan-chefs-preserving-traditional-cuisine
2•n1b0m•1h ago•0 comments

The iPad's Software Problem Is Permanent [video]

https://www.youtube.com/watch?v=bnYLpA5kAbo
1•tosh•1h ago•0 comments

Simple 3D Packing

https://github.com/Vrroom/psacking
2•matroid•1h ago•1 comments