frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•7mo ago

Comments

kemotep•7mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

AIxCC Curl Details

https://daniel.haxx.se/blog/2025/10/22/aixcc-curl-details/
1•robin_reala•5m ago•0 comments

Fossils, genomes clash as scientists debate the mosquito's origins

https://www.thehindu.com/sci-tech/science/fossils-genomes-clash-as-scientists-debate-the-mosquito...
1•ashishgupta2209•6m ago•0 comments

Kafkorama Benchmark: 1M msgs/s to 1M users on Confluent with 5ms median latency

https://kafkorama.com/blog/benchmarking-kafkorama-confluent.html
1•michelrotaru•6m ago•0 comments

All the buildings available as 3D models

https://www.tum.de/en/news-and-events/all-news/press-releases/details/all-the-worlds-buildings-av...
1•taubek•7m ago•0 comments

AI Assist is now available on Stack Overflow

https://meta.stackexchange.com/questions/415115/ai-assist-is-now-available-on-stack-overflow
1•atomicnature•9m ago•0 comments

Morphisms All the Way Down: API Design as Arrow-First Thinking

https://ibrahimcesar.cloud/blog/categorical-solutions-architect-part-2/
1•ibrahimcesar•10m ago•0 comments

Publishing a Java-Based Database Tool on Mac App Store (Mas)

https://tanin.nanakorn.com/publishing-a-java-based-database-tool-on-mac-app-store-mas/
1•pjmlp•11m ago•0 comments

Show HN: Paaage – Minimalist, drag-and-drop homepage builder

https://paaage.app
1•PatriceC•12m ago•0 comments

News gets reshaped to match the way your brain works

https://www.niemanlab.org/2025/12/news-gets-reshaped-to-match-the-way-your-brain-works/
1•giuliomagnifico•17m ago•0 comments

Are most sentences unique? An empirical examination of Chomskyan claims

https://arxiv.org/abs/2509.19108
1•bryanrasmussen•18m ago•0 comments

Does YC support startups paying the 100K$ H1B fee to import talents?

2•blobembassay•20m ago•0 comments

Linux Kernel Version Numbers

http://www.kroah.com/log/blog/2025/12/09/linux-kernel-version-numbers/
1•JNRowe•23m ago•0 comments

Cashfree Payments Powers High-Scale, Speed-First Support

https://tech.cashfree.com/4-ways-cashfree-payments-powers-high-scale-speed-first-support-d93ac85e...
1•manishajayson•23m ago•0 comments

Why are there so many react developers?

2•blobembassay•23m ago•1 comments

Google Maps allocates survival across London's restaurants

https://laurenleek.substack.com/p/how-google-maps-quietly-allocates
2•justincormack•24m ago•0 comments

I'm Not AI, I'm Just Autistic

https://www.latoyarachelle.com/im-not-ai-im-just-autistic/
3•sodic•24m ago•0 comments

Building a Databricks Jobs Error Monitoring Dashboard

https://medium.com/dev-genius/building-a-databricks-jobs-error-monitoring-dashboard-a72f90650c87
1•protmaks•25m ago•0 comments

The Invisible Iceberg of AI Technical Debt

https://old.reddit.com/r/AIQuality/comments/1m83846/the_invisible_iceberg_of_ai_technical_debt/
1•PranayBatta•28m ago•1 comments

Show HN: I revived Spotify-TUI (now Spotatui) with native streaming and updates

https://github.com/LargeModGames/spotatui
1•LargeModGames•29m ago•1 comments

Show HN: Vieta Space, a visual LaTeX math editor

https://docs.vietaspace.com/guide/features
3•liamhawtin•33m ago•1 comments

'Alan's Universe' Shows What It Might Look Like to Win at YouTube

https://www.nytimes.com/2025/12/09/arts/television/youtube-alans-universe.html
2•fleahunter•37m ago•0 comments

Bascetta Star

https://mathematische-basteleien.de/bascettastar.htm
1•coolius•39m ago•0 comments

Spied: BMW's First Electric M Car

https://www.thedrive.com/news/2027-bmw-ix3-m-spy-shots
1•PaulHoule•39m ago•0 comments

Show HN: Bifrost – open-source LLM Gateway (50x lower latency than LiteLLM)

https://github.com/maximhq/bifrost
3•dskuldeep•40m ago•0 comments

Springer Nature retracts ~40 publications that trained ANNs on 'bonkers' dataset

https://www.thetransmitter.org/retraction/exclusive-springer-nature-retracts-removes-nearly-40-pu...
2•sundarurfriend•42m ago•0 comments

Show HN: A Werewolf-style puzzle with zero lying

https://www.cluesofwho.com/
1•soasme•43m ago•0 comments

Apple will not let me join the Developer Program – and will not say why

https://yomuapp.kulman.sk/support
2•tectiv3•45m ago•1 comments

PeerTube V8: manage your videos with your team

https://framablog.org/2025/12/09/peertube-v8-manage-your-videos-with-your-team/
6•tcit•45m ago•0 comments

Whitehall rejects £1.8B digital ID price tag – but won't say what it will cost

https://www.theregister.com/2025/12/09/uk_digital_id_costs/
1•jjgreen•45m ago•0 comments

Compiler Engineering in Practice – Part 1: What Is a Compiler?

https://chisophugis.github.io/2025/12/08/compiler-engineering-in-practice-part-1-what-is-a-compil...
1•todsacerdoti•46m ago•0 comments