frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Find the right AI agents to build

https://www.agentideahub.com
1•mattmerrick•24s ago•0 comments

TUI email client in native Golang with LLM based drafting functions

https://mail.intellios.ai
1•coolwulf•2m ago•0 comments

Nomad: Portable, offline media server powered by the ESP32-S3 in a thumbdrive

https://www.instructables.com/Jcorp-Nomad-Mini-WIFI-Media-Server/
1•thunderbong•2m ago•0 comments

US allows Anthropic to release Mythos AI to 'trusted' US organizations

https://www.reuters.com/technology/us-releases-anthropic-model-mythos-some-us-companies-semafor-r...
1•swolpers•2m ago•0 comments

If they start to gatekeep who gets to use the best models, that is a DoW

https://twitter.com/jmrphy/status/2070528497752166454
1•Jimmc414•3m ago•0 comments

Show HN: I replaced $500/mo in freelance tools with 20 ChatGPT prompts

https://medium.com/@promptalex53/1c857c6f424a
1•promptalex53•7m ago•0 comments

WordStar: A Writer's Word Processor (1996)

https://www.sfwriter.com/wordstar.htm
1•droidjj•8m ago•0 comments

Meta asks California lawmakers for shield from child harm penalties

https://www.politico.com/news/2026/06/26/exclusive-meta-asks-california-lawmakers-for-shield-from...
1•donsupreme•11m ago•0 comments

Smugglers Create Fake Google Maps Car, US Border Patrol Catches

https://www.autoevolution.com/news/smugglers-create-fake-google-maps-car-border-patrol-agents-act...
1•gnabgib•16m ago•0 comments

Ask HN: MacBook vs. Dedicated GPU for LLM

2•mzubairtahir•20m ago•1 comments

OpenData – Open-Source and Object Store Native Databases

https://www.opendata.dev/
1•apurvamehta•24m ago•0 comments

Love Conquers Fear: Humanity, AI, and the Age of Abundance for All

https://www.amazon.com/Love-Conquers-Fear-Humanity-Abundance-ebook/dp/B0GX32NPX5
1•ilreb•29m ago•0 comments

Boeing 777 makes dangerous ~25ft low pass over Horseshoe Bay Resort Jet Center

https://twitter.com/EBaviation/status/2069953669710110852
2•leetrout•34m ago•0 comments

Threats to US payment rails helped trigger Bessent's AI worries

https://www.semafor.com/article/06/26/2026/bessent-engaged-on-ai-following-warnings-about-fed-pay...
1•tiahura•36m ago•0 comments

Kohana, a prediction market where you write the question

https://kohana.xyz/
1•melan13•41m ago•0 comments

Rheinmetall gambled on Germany's doomed warship project – and lost

https://www.ft.com/content/e3fa2351-72bd-40e1-97e0-5a6ae0a63a2b
2•JumpCrisscross•49m ago•1 comments

Where production policy belongs: building Eliya in public

https://foojay.io/today/where-production-policy-belongs-building-eliya-in-public/
2•fahimfarookme•51m ago•3 comments

Anatomy of a Failed (Nation-State?) Attack

https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/
2•signa11•56m ago•0 comments

Ornith-1.0: Self-Scaffolding LLMs for Agentic Coding

https://deep-reinforce.com/ornith_1_0.html
3•modinfo•58m ago•0 comments

Ukrainian Attacks Spur State of Emergency Declaration in Crimea

https://www.nytimes.com/2026/06/26/world/europe/crimea-ukraine-state-emergency.html
4•JumpCrisscross•58m ago•0 comments

Codex-maxxing for long-running work

https://openai.com/index/codex-maxxing-long-running-work/
1•gmays•1h ago•0 comments

Software Is Becoming Marketing

https://www.terezatizkova.com/writing/software-abundance
2•tylerdane•1h ago•0 comments

Cybersecurity firms targeted by fraudulent OpenAI organization invites

https://www.bleepingcomputer.com/news/security/cybersecurity-firms-targeted-by-fraudulent-openai-...
1•Timofeibu•1h ago•0 comments

For Peter

https://lucybellwood.com/for-peter/
3•wonger_•1h ago•1 comments

How China Is Gutting Western Automakers (2025)

https://newsletter.dunneinsights.com/p/how-china-is-gutting-western-automakers
1•toomuchtodo•1h ago•0 comments

A man who did nothing, brilliantly

https://theidlegazette.beehiiv.com/p/the-man-who-did-nothing-brilliantly-5
1•vinhnx•1h ago•0 comments

Accidental Anonymity

https://macwright.com/2026/06/24/accidental-anonymity
1•herbertl•1h ago•0 comments

National College Entrance Examination Collection - Math – China

https://github.com/deekur/gaokaomath
1•pm2222•1h ago•0 comments

Daytona is going closed source. Here's why

https://www.daytona.io/dotfiles/updates/daytona-is-going-closed-source
4•david_shi•1h ago•1 comments

Thermodynamic gravity explains cosmic acceleration without dark energy

https://phys.org/news/2026-06-thermodynamic-approach-gravity-cosmic-dark.html
3•stevenjgarner•1h ago•1 comments