frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Fabricated citations: an audit across 2·5M biomedical papers

https://www.thelancet.com/journals/lancet/article/PIIS0140-6736(26)00603-3/fulltext
1•ep_jhu•33s ago•0 comments

Fifteen Portugese police officers detained in torture investigation

https://www.bbc.com/news/articles/c0r2zq9wg9xo
1•lastdong•43s ago•0 comments

Engineering Intelligence from Autocomplete

https://www.szia.ai/post/engineer-intelligence-from-autocomplete
1•mszel•1m ago•0 comments

Certificate Issuance through Let's Encrypt unavailable

https://www.cloudflarestatus.com/incidents/z3vgxxfvt3yb
1•hosteur•2m ago•0 comments

Why technology made the world richer and rich countries feel poorer

https://aesium22.substack.com/p/the-two-speed-economy
1•-__hn__-•2m ago•0 comments

The American, Intense World of High-School Debate

https://www.newyorker.com/magazine/2026/05/11/the-very-american-very-intense-world-of-high-school...
1•limitedfrom•2m ago•0 comments

AI's Big Messaging Pivot

https://www.noahpinion.blog/p/ais-big-messaging-pivot
1•paulpauper•3m ago•0 comments

Could development economics be more useful?

https://www.noahpinion.blog/p/could-development-economics-be-more
1•paulpauper•4m ago•0 comments

A simple point about diversification

https://marginalrevolution.com/marginalrevolution/2026/05/a-simple-point-about-diversification.html
1•paulpauper•5m ago•0 comments

Dirty Frag: Universal Linux LPE

https://github.com/V4bel/dirtyfrag
2•unbeli•5m ago•0 comments

Digg Is Back (Again)

2•basket278•7m ago•0 comments

NocTUI – Lightweight C Library for Building Terminal User Interfaces (TUIs)

https://github.com/UsboKirishima/noctui
1•333revenge•8m ago•0 comments

Real-Time Vibrotactile Stimulation and Inter-Brain Connectivity in Partner Dance

https://dl.acm.org/doi/10.1145/3731459.3773332
1•bookofjoe•8m ago•0 comments

Arena Physica

https://www.arenaphysica.com
1•skogstokig•9m ago•0 comments

Notes on Tanya M. Luhrmann's Book 'How God Becomes Real'

https://michaelnotebook.com/luhrmann/index.html
1•benbreen•10m ago•0 comments

Divorce Rates by Occupation

https://flowingdata.com/2026/05/07/divorce-and-occupation-2026/
3•tevon•16m ago•0 comments

Internet Archive Switzerland: Expanding a Global Mission to Preserve Knowledge

https://blog.archive.org/2026/05/06/internet-archive-switzerland-expanding-a-global-mission-to-pr...
4•rbanffy•17m ago•1 comments

Everything Vault – a local-first Markdown knowledge system for LLMs

https://github.com/AntlerForge/everything-vault
3•AntlerForge•19m ago•0 comments

From MemSQL to HorizonDB, an Engineer's Journey with Adam Prout

https://talkingpostgres.com/episodes/from-memsql-to-horizondb-an-engineers-journey-with-adam-prout
1•clairegiordano•23m ago•0 comments

When is your birthday? – The Math Behind Hash Collisions

https://0xkrt26.github.io/math_behind_security/2026/05/08/birthday-problem.html
1•denismenace•24m ago•0 comments

Beyond Human Syntax – The Logic of Future Coding Agents

https://www.thebigdatablog.com/nela-beyond-human-syntax-the-logic-of-future-coding-agents/
3•heikowag•24m ago•0 comments

AI, the Poor, and the Ignorant

https://user8.bearblog.dev/ai-the-poor-and-the-ignorant/
1•James72689•26m ago•0 comments

Using Claude Code: The Unreasonable Effectiveness of HTML

https://twitter.com/trq212/status/2052809885763747935
3•tchalla•28m ago•0 comments

Real-time collaboration will not ship in WordPress 7.0

https://make.wordpress.org/core/2026/05/08/rtc-removed-from-7-0/
1•pentagrama•29m ago•0 comments

A 3D explorer of the Bitcoin blockchain

https://blockparty-omega.vercel.app/
1•dca_mindset•29m ago•0 comments

1k-year-old archaeological site bulldozed during construction of border wall

https://www.theartnewspaper.com/2026/05/05/border-wall-construction-bulldozes-archaeological-site
1•YeGoblynQueenne•30m ago•0 comments

Félix Guattari – The Image Machine (1990)

https://www.e-flux.com/notes/6783490/the-image-machine
2•bondarchuk•30m ago•0 comments

Frontier models refuse to help organizers, so we built our own activist AI

https://www.outcryai.com/research/how-to-create-activist-ai
2•micahwhite•31m ago•0 comments

Rolo: Relationship Intelligence Tool

https://rolo.agentschool.io/
2•amahjoor•32m ago•0 comments

If You Read One Screenwriting Book, Read This

https://jamesgarside.substack.com/p/if-you-read-one-screenwriting-book
1•monkeymagick•33m ago•0 comments