frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•10mo ago

Comments

kemotep•10mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Apple at 50: Five Decades of Thinking Different [video]

https://www.youtube.com/watch?v=w8wt0LBCjXM
1•vinhnx•3m ago•0 comments

Extra Timezones on You Mac Menubar

https://apps.apple.com/gb/app/zoneclock-toolbar-clock/id6760158037?mt=12
1•alepacheco-dev•5m ago•0 comments

WireGuard Is Two Things

https://www.proxylity.com/articles/wireguard-is-two-things.html
2•mlhpdx•10m ago•0 comments

Anyone else having GitHub Actions fail?

2•munksbeer•10m ago•1 comments

White House AI Video Tweet

https://twitter.com/WhiteHouse/status/2031895801064985021
1•csomar•13m ago•1 comments

Ever Onward IBM [video]

https://www.youtube.com/watch?v=L9oh3gqOEKU
1•walterbell•25m ago•0 comments

Why are so many statues naked? An art historian explains its ancient roots

https://theconversation.com/why-are-so-many-statues-naked-an-art-historian-explains-this-traditio...
2•1659447091•25m ago•0 comments

PhDs and other experts making $16/HR training AI to kill their own jobs

https://nymag.com/intelligencer/article/white-collar-workers-training-ai.html
3•suzzer99•28m ago•1 comments

The Bold Environmental Vision of President Jimmy Carter

https://www.motherjones.com/politics/2024/12/president-jimmy-carter-death-100-environmental-legac...
2•altilunium•30m ago•0 comments

US intelligence says Iran government is not at risk of collapse

https://www.reuters.com/business/media-telecom/us-intelligence-says-iran-government-is-not-risk-c...
5•tartoran•31m ago•2 comments

Why are some stars always visible while others come and go with the seasons

https://theconversation.com/why-are-some-stars-always-visible-while-others-come-and-go-with-the-s...
3•1659447091•37m ago•0 comments

Hightitan, a lightweight framework for high-concurrency data streaming

1•HIGHTITAN•40m ago•0 comments

Offline Computing

https://robertsdotpm.github.io/software_engineering/offline_computing.html
3•Uptrenda•41m ago•0 comments

Ask HN: Built API monitor with root cause analysis – unable to find first users

1•acrtic•44m ago•2 comments

.ORG Domain Price Increases June 1, 2026

4•ommz•45m ago•2 comments

Show HN: AutoICD API – AI clinical coding platform for ICD-10 and SNOMED

https://autoicdapi.com
1•FedeUY•48m ago•0 comments

Everyone's new favorite protein bar hit with class-action lawsuit over calories

https://www.nbcnewyork.com/news/david-protein-bar-calories-class-action-lawsuit/6475387/
2•randycupertino•51m ago•1 comments

Quantsynth – Forecast evaluation and dataset analysis before modeling

https://quantsynth.org/
1•slyyyy•53m ago•1 comments

Show HN: MCP server for ICD-10 and SNOMED clinical coding

https://github.com/fcggamou/autoicd-mcp
1•FedeUY•55m ago•0 comments

Tetris Is Hard with Just One Piece Type

https://arxiv.org/abs/2603.09958
2•bmc7505•1h ago•0 comments

Why Big Nations Lose Small Wars: The Politics of Asymmetric Conflict

https://www.researchgate.net/publication/259380603_Why_Big_Nations_Lose_Small_Wars_The_Politics_o...
4•rramadass•1h ago•1 comments

I Stopped Writing Prompts and Started Writing Systems

https://medium.com/@robert.shane.kirkpatrick/i-stopped-writing-prompts-and-started-writing-system...
2•totalvaluegroup•1h ago•2 comments

Fossil Version 2.28

https://fossil-scm.org/home/info/version-2.28
1•chungy•1h ago•1 comments

The United States Could Lose the Gulf

https://foreignpolicy.com/2026/03/05/iran-israel-united-states-war-gulf-countries-alliances/
4•ParentiSoundSys•1h ago•0 comments

Oil hits $100 a barrel despite deal to release record amount of reserves

https://www.bbc.com/news/articles/c1w5141vx53o
40•tartoran•1h ago•40 comments

Procreate Dreams 2

https://procreate.com/dreams
1•twalichiewicz•1h ago•0 comments

Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/
36•2bluesc•1h ago•0 comments

'Web Kit' vs. 'WebKit' (2006)

https://daringfireball.net/2006/05/web_kit_vs_webkit
5•dddddaviddddd•1h ago•0 comments

I Built an Agent First Micro SaaS

https://mochipdf.com
2•cbolgiano•1h ago•2 comments

Show HN: Live Kaiwa – real-time Japanese conversation support

https://livekaiwa.com/login
1•diasks2•1h ago•0 comments