frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Enterprise AI Agents Are Leaving the Server

https://focused.io/lab/enterprise-ai-agents-are-leaving-the-server
1•mooreds•3m ago•0 comments

British forces intercept Russian shadow fleet tanker in the Channel

https://www.reuters.com/world/europe/uks-starmer-says-armed-forces-intercepted-russian-shadow-fle...
1•MilnerRoute•3m ago•0 comments

I built a defense procurement marketplace – free for vendors

https://birka.ai
1•jaywashere•4m ago•0 comments

Agentic Credit Card MCP

https://robinhood.com/us/en/support/articles/agentic-credit-card/
1•barbacoa•16m ago•0 comments

Pyhn 0.4.0: Hacker News in your terminal

https://github.com/toxinu/pyhn
3•toxinu•20m ago•0 comments

Surge in scams as fraudsters use AI to target people

https://www.bbc.com/news/articles/cwykp9ygxlvo
1•1659447091•22m ago•0 comments

Monitoring LLM Inference with Prometheus and Grafana (vLLM, TGI, Llama.cpp)

https://www.glukhov.org/observability/monitoring-llm-inference-prometheus-grafana/
1•nryoo•25m ago•0 comments

Even More Batteries Included with Emacs

https://karthinks.com/software/even-more-batteries-included-with-emacs/
2•signa11•29m ago•0 comments

The next frontier of innovation is coming back to the physical world

https://productnow.ai/blogs/a-dose-of-hope-for-the-future
1•kadhirvelm•34m ago•0 comments

Smashed Toilet Phone Web Server

https://www.offthebricks.com/articles/smashed-toilet-phone-web-server
2•mircerlancerous•40m ago•0 comments

DBOS Network Sensing: A Web Services Approach to Collaborative Awareness

https://arxiv.org/abs/2509.09898
2•teleforce•41m ago•0 comments

Decouple the Agent: Why Prompts, Tools, and Models Don't Belong in Your Client

https://vivgrid.com/decoupling-prompts-tools-models-from-agent-client
4•fanweixiao•41m ago•0 comments

AI Has Amnesia. Here's Every System Built to Fix It

https://medium.com/@alanayalag/your-ai-has-amnesia-heres-every-system-built-to-fix-it-ad7dee117a75
3•AlanAAG•43m ago•0 comments

Ask HN: How do you design CLIs for agents?

2•vokneruk•48m ago•0 comments

Lsp85 – an lsp for the Intel 8085 assembly

2•irhs•48m ago•0 comments

Show HN: Go-To-Market for Engineers article series

https://supramono.com/blog/go-to-market-for-engineers-distribution-is-the-product/
3•supramono•57m ago•0 comments

Netlify Drop

https://app.netlify.com/drop
2•skogstokig•57m ago•0 comments

Tech's Next IPO Wave Promises a Charitable Windfall

https://www.wsj.com/finance/investing/techs-next-ipo-wave-promises-a-charitable-windfall-885a1e74
3•builtbystef•1h ago•0 comments

iOS 27's Reworked Stub Islands

https://codecolor.ist/posts/2026-06-15-ios27-reworked-stub-islands/
3•gok•1h ago•0 comments

Argentina Wants to Let AI Own Companies. Here's What That Means

https://www.forbes.com/sites/anishasircar/2026/06/10/ai-owned-companies-argentina/
4•pseudolus•1h ago•1 comments

CoCoMS (Construction Correspondence Management System)

2•cmina•1h ago•0 comments

Sync – Quality Control and Project Management System for AI Agents

https://sync.buzz
2•nikolai_evseev•1h ago•0 comments

Polis – the #1 tool for AI agent coordination

https://polis-protocol.vercel.app/#
2•lucius_gc•1h ago•0 comments

Why You Need to Become a Neuro-Punk Right Now

https://medium.com/@artem-x/why-you-need-to-become-a-neuro-punk-right-now-f266223ac440
2•theorchid•1h ago•0 comments

US and Iran reach cease fire agreement

https://www.nytimes.com/live/2026/06/14/world/iran-war-trump-us
4•koolba•1h ago•0 comments

Molecular Diversity as a Biosignature

https://www.nature.com/articles/s41550-026-02864-z
2•wslh•1h ago•0 comments

Kevin Warsh Wants the Fed to Stop Explaining Everything

https://www.wsj.com/economy/central-banking/fed-warsh-chair-communication-d2f2d226
3•Cider9986•1h ago•1 comments

BEAVER: Enterprise benchmark for LLM Text-to-SQL from private data warehouses

https://beaverbench.github.io/
2•teleforce•1h ago•0 comments

Show HN: Astro Sidey – A simple, minimalistic personal blog theme

https://github.com/odhyp/astro-sidey
2•odhy•1h ago•0 comments

Your Database Is the Bottleneck. Not Your Code

https://howtocenterdiv.com/beyond-the-div/your-database-is-the-bottleneck-not-your-code
3•mooreds•1h ago•0 comments