frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Show HN: PauseRead – hosted read-later with Pocket HTML import

https://pauseread.com/pocket-alternative
1•YuriiKholodkov•20s ago•1 comments

Infamous Front-Running Crypto Bot Gets Tricked and Drained for $7.5M

https://gizmodo.com/infamous-front-running-crypto-bot-jaredfromsubway-gets-tricked-and-drained-fo...
2•cainxinth•1m ago•0 comments

Accenture shares fall to lowest since 2017 as AI threat mounts

https://www.ft.com/content/9f063b07-da39-4feb-92ab-ee0f91385c62
3•JumpCrisscross•1m ago•0 comments

Information and Attention (1971)

https://www.iecodesign.com/blog/2025/8/4/information-and-attention
2•RickJWagner•2m ago•0 comments

Grid Generator

https://codequest.work/generator/grid/en/
2•ORECTIC•3m ago•0 comments

Show HN: Taqta. Made an Are.na-style visual boards for Obsidian

https://github.com/djakish/obsidian-taqta
2•wasdwasdwasd•4m ago•0 comments

Apple Internals: Swift in the Kernel – By Josh Maine

https://blog.calif.io/p/apple-internals-swift-in-the-kernel
2•rbanffy•5m ago•0 comments

Just because each item makes sense doesn't mean they make sense together

https://blog.osull.com/2026/06/22/just-because-each-item-makes-sense/
2•danosull•5m ago•0 comments

Scanned React source code: 659 security issues, one real GitHub token found

https://github.com/xiaohou2503687-design/guardrail
3•shipfastcli•5m ago•0 comments

A Bitter Lesson for Memory

https://personal-website-3bed.onrender.com/blog-viewer.html?slug=A%20Bitter%20Lesson%20for%20Memory
2•wenhan_zhou•5m ago•1 comments

Is Anyone Else Excited by Swift's Progress as a Language? – Fatbobman's Weekly

https://weekly.fatbobman.com/p/fatbobmans-swift-weekly-141
3•fatbobman•5m ago•0 comments

Stargazing

https://www.futilitycloset.com/2026/06/15/stargazing/
2•surprisetalk•6m ago•0 comments

JSON Inspector – an offline-first Chrome extension to view and query JSON

https://chromewebstore.google.com/detail/jstools-json-inspector/dkgnmlmlpipjoabeolnfnpkkfmcbcjmj
2•javatuts•6m ago•0 comments

Binance set to lose permission to operate in Europe

https://www.reuters.com/business/finance/binance-set-lose-eu-licence-bid-permission-offer-service...
4•darktoto•8m ago•0 comments

Squidbleed

https://blog.calif.io/p/squidbleed-cve-2026-47729
2•Tomte•10m ago•0 comments

SpaceX Shares Poised to Fall Again as US Market Reopens

https://www.bloomberg.com/news/articles/2026-06-22/spacex-shares-poised-to-slide-again-as-us-mark...
3•johnbarron•11m ago•0 comments

How to Fix Bay Area Transit [pdf]

https://ti.org/pdfs/BayAreaTransit.pdf
2•xnx•13m ago•1 comments

Show HN: Lockin – system-level distraction blocker controlled via text

https://www.lockinmcp.com
2•Kiog-Aser•13m ago•0 comments

I Shot Films for 30 Years. Now I'm Building Safety Systems for AI Agents

https://maref.org/blog/from-steadicam-to-agent-governance
2•Athena-maref•14m ago•0 comments

Resolving Uncertainty: A Unified Overview of Rabbinic Methods [pdf]

https://u.cs.biu.ac.il/~koppel/rov-25.5.pdf
3•FergusArgyll•16m ago•0 comments

When Diets Don't Work: Parents Turn to Wegovy for Elementary School Kids

https://www.wsj.com/health/wellness/when-diets-dont-work-parents-turn-to-wegovy-for-elementary-sc...
2•JumpCrisscross•16m ago•0 comments

Show HN: Bowora – A launchpad for build-in-public founders

https://bowora.com
2•Nimaaksoy•20m ago•0 comments

Show HN: Appareo – For when you know what you want to say but can't write it

https://www.appareo.ink/
3•ShaunakInamdar•21m ago•0 comments

You Have the Pieces. Now Build It

https://www.theidentityunderground.com/post/you-already-have-the-pieces-now-build-it
2•mooreds•22m ago•0 comments

Instagram sued over illegal gambling ads in the Nederland

https://nltimes.nl/2026/06/22/instagram-sued-illegal-gambling-ads-featuring-virgil-van-dijk-ronaldo
4•giuliomagnifico•23m ago•0 comments

Llama-dash – One go-to control plane for local inference

https://llama-dash.dev
2•ndom91•24m ago•1 comments

The Things We Share

https://codeplusconduct.substack.com/p/the-things-we-share
2•mooreds•25m ago•0 comments

How Accurate Is Professor Jiang?

https://predictivehistory.com/prediction-tracker/
3•mooreds•26m ago•1 comments

Any Sufficiently Large Lookup Table Must Be Conscious

https://julianrdcosta.substack.com/p/any-realizable-implementation-of
2•Anon84•27m ago•0 comments

Alan Greenspan, former chairman of the Fed, dies at age 100

https://www.cnbc.com/2026/06/22/alan-greenspan-former-chairman-of-the-fed-dies-at-age-100.html
4•jacquesm•28m ago•0 comments