frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

VGA memory access is complicated

https://www.os2museum.com/wp/learn-something-old-every-day-part-xxi-vga-memory-access-is-complica...
1•bananaboy•47s ago•0 comments

Natural Language Autoencoders Produce Unsupervised Explanations LLM Activation

https://transformer-circuits.pub/2026/nla/
1•Anon84•54s ago•0 comments

The Dome: A Simple Violation of Determinism in Newtonian Mechanics

https://sites.pitt.edu/~jdnorton/Goodies/Dome/index.html
2•antiquark•8m ago•0 comments

Show HN: I built an MCP server for narrative-driven trading intelligence

2•anish_mitta•11m ago•0 comments

Show HN: Origami – A simple workspace-oriented terminal manager

https://tryorigami.app
2•uniqid•12m ago•0 comments

Porn website at center of CNN investigation into sexual abuse taken offline

https://www.cnn.com/2026/05/08/europe/porn-site-motherless-taken-down-dutch-authorities-intl
2•Bender•12m ago•0 comments

Microsoft doesn't want you to know this [video]

https://www.youtube.com/watch?v=iuIdBfjL62s
2•janalsncm•14m ago•0 comments

Devon

https://grimfandango.substack.com/p/devon
2•lastdong•20m ago•0 comments

LinkLens: Protect Yourself from Clickbait

https://chromewebstore.google.com/detail/linklens/dbfidmikilfcnkngenffkinmknoblaap
2•philstahlfeld•20m ago•0 comments

After banning foreign routers, FCC says existing ones can get updates until 2029

https://arstechnica.com/tech-policy/2026/05/fcc-slightly-relaxes-foreign-router-ban-allows-softwa...
5•Bender•20m ago•1 comments

Chinese Powev Enters DDR5 Market with Up to 64 GB Udimm, Sodimm, and Rdimm

https://www.techpowerup.com/348936/chinese-powev-enters-ddr5-market-with-up-to-64-gb-udimm-sodimm...
5•SockThief•20m ago•0 comments

A Caddy Cert Expired Because Systemd-Resolved Was Selectively Broken

https://rant.mvh.dev/a-caddy-cert-expired-because-systemd-resolved-was-selectively-broken/
2•PaulHoule•22m ago•0 comments

Closure of Radio 4 on Long Wave (LW)

https://www.bbc.co.uk/reception/work-warning/news/radio4lw
3•austinallegro•25m ago•0 comments

A brain reward circuit inhibited by next-generation weight-loss drugs in mice

https://www.nature.com/articles/s41586-026-10444-4
2•Bender•25m ago•0 comments

I Disagree with Paul Graham

https://mrmarket.bearblog.dev/i-disagree-with-paul-graham/
2•seltzerboys•26m ago•0 comments

Show HN: Route optimization API that solves fleet planning as a single problem

https://demo.vepathos.com
1•pantherolive•26m ago•0 comments

PostHog Code

https://posthog.com/code
1•smitec•34m ago•0 comments

When readers would rather listen

https://blog.keyvan.net/p/ai-voiced-narration-for-articles
1•k1m•34m ago•0 comments

An Ice Cold Take on CI Config Systems

https://v5.chriskrycho.com/notes/an-ice-cold-take-on-ci-config-systems/
1•mooreds•35m ago•0 comments

K-12's biggest failure is making us think learning ends

https://twitter.com/NirZicherman/status/2053963176929116171
1•tattattaei•36m ago•1 comments

Red flags when building AI

https://www.dianapfeil.com/ai/2026/02/11/red-flags-when-building-ai.html
2•mooreds•39m ago•0 comments

AI is a Sword not a Shield [video]

https://www.youtube.com/watch?v=TdbMZRlTDaI
1•saltysalt•41m ago•0 comments

Typing Some Python Quirks

https://blog.mathieui.net/typing-python-quirks.html
1•Einenlum•41m ago•0 comments

A million baby monitors and security cameras were easily viewable by hackers

https://www.theverge.com/tech/926487/meari-technology-hack-baby-monitor-security-camera
3•starkparker•42m ago•0 comments

Ask HN: How are you preparing for interviews nowadays?

3•holden_nelson•45m ago•2 comments

Show HN: Compiled an archive of copium content for SF Bay Area engineers

https://copium.fyi/
1•average_ana•47m ago•0 comments

Uniform Rental Contracts Explain the U.S. Economy

https://www.thebignewsletter.com/p/fine-print-how-uniform-rental-contracts
2•connor11528•47m ago•0 comments

What Challenging a Bowling Monopoly Says About America

https://www.thebignewsletter.com/p/monopoly-round-up-what-challenging
1•connor11528•48m ago•0 comments

Counterfactual samples synthesizing for mitigating hallucination in LLMs

https://pubmed.ncbi.nlm.nih.gov/41729914/
1•fragmede•54m ago•1 comments

Tashk – a todo manager written in pure bash

https://github.com/agamoaltrove/tashk
2•agamoaltrove•56m ago•0 comments