frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Destroy Big Tech with a Salvaged Cyberdeck – Make

https://makezine.com/article/technology/raspberry-pi/destroy-big-tech-with-a-salvaged-cyberdeck/
1•evo_9•1m ago•0 comments

Me in 2026 – What is tech doing?

https://ivanlugo.dev/writing/first-words/
1•tikimcfee•1m ago•1 comments

Ask HN: Are you interested in building devtools/infra for science?

1•rorytbyrne•2m ago•0 comments

Using encapsulated development to code on my phone

https://maryrosecook.com/blog/post/using-encapsulated-development-to-code-on-my-phone
1•evakhoury•2m ago•0 comments

FBI warns of in-person data theft attacks from extortion gang

https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-th...
1•Brajeshwar•3m ago•0 comments

Meta Smart Glasses Covert Spying Bypass: Verified, Unresolved, Tested

https://ipvm.com/reports/meta-smart-glasses-covert-spying
1•jhonovich•4m ago•0 comments

Provedex: Tamper-evident audit logs for AI agents (Pipecat, LangChain)

https://github.com/provedex/provedex
1•adi-suresh•4m ago•0 comments

Vim Vim Revolution

https://vimvimrevolution.com/
1•kevinlinxc•4m ago•1 comments

We contain Claude across products

https://www.anthropic.com/engineering/how-we-contain-claude
1•skogstokig•5m ago•0 comments

Franchising has quietly made countless Americans rich

https://www.economist.com/business/2026/05/24/franchising-has-quietly-made-countless-americans-rich
1•bookofjoe•5m ago•1 comments

Google AI Threat Defense to help you outpace the adversary

https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense
3•srameshc•6m ago•0 comments

Last.fm is now independent

https://support.last.fm/t/last-fm-is-now-independent/118591
1•twistslider•6m ago•0 comments

The Viruses Causing New Outbreaks Are Less Familiar to Science

https://www.nytimes.com/2026/05/27/science/ebola-hantavirus-species-strains.html
1•digital55•7m ago•0 comments

The Farmers Who Fought a Data Centre–and Won

https://macleans.ca/longforms/the-farmers-who-fought-a-data-centre-and-won/
1•speckx•7m ago•0 comments

[hand-drawn] recipes for laid-back engineers

https://leontrolski.github.io/recipes.html
1•guessmyname•9m ago•0 comments

Show HN: Approve Claude CLI prompts from the browser, phone, or tablet

https://notifai.net/
2•Witness327•9m ago•1 comments

Now, imagine other people are different from you (2019)

https://blog.jobelenus.dev/blog/now-imagine-other-people-are-different-from-you/
1•mooreds•11m ago•0 comments

An Update on Composer and Packagist Supply Chain Security

https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
4•Seldaek•11m ago•0 comments

Who buys custom chips and why?

https://substack.com/@johncoleisreading/note/c-263273279
1•johncole•12m ago•0 comments

LLM, meet ML pipeline. ML pipeline, meet your new build step

https://matthias-kainer.de/blog/posts/llm-meet-ml-pipeline/
2•oesimania•13m ago•0 comments

Transparent solar cells could be mounted right on windows

https://newatlas.com/energy/transparent-solar-cells-windows/
1•breve•13m ago•0 comments

A One-Character Host Header Bug in Starlette Exposed AI Agents

https://firethering.com/badhost-starlette-critical-vulnerability-ai-agents/
1•steveharing1•13m ago•0 comments

The Biggest and Weirdest Commits in Linux Kernel Git History (2017)

https://www.destroyallsoftware.com/blog/2017/the-biggest-and-weirdest-commits-in-linux-kernel-git...
1•downbad_•15m ago•0 comments

IBM's Video Explaining Five AI Risks That Can Get You Fired

https://www.youtube.com/watch?v=1m55T8xST9s
1•busymom0•15m ago•0 comments

Katharos: Monads, functors, and immutable data for Python

https://github.com/kamalfarahani/katharos
1•h8hawk•15m ago•0 comments

Ubuntu releases Workshops: Sandboxed dev environments in a single command

https://discourse.ubuntu.com/t/introducing-workshop-launch-sandboxed-development-environments-on-...
2•nullbio•16m ago•0 comments

The AI fight brewing inside The New York Times

https://www.theverge.com/ai-artificial-intelligence/937689/new-york-times-tech-guild-ai-monitorin...
3•Brajeshwar•17m ago•0 comments

» Planescape: Torment, Part 1: From the Tabletop

https://www.filfre.net/2026/05/planescape-torment-part-1-from-the-tabletop/
1•ibobev•17m ago•0 comments

C++26: Ordering of constraints involving fold expressions

https://www.sandordargo.com/blog/2026/05/27/cpp26-constraints-ordering-fold-expressions
1•ibobev•18m ago•0 comments

Does bulk memmove speed up `std:remove_if`? (No.)

https://quuxplusone.github.io/blog/2026/05/23/chunked-remove/
1•ibobev•18m ago•0 comments