frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•10mo ago

Comments

kemotep•10mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Iranian cryptoasset outflows surge 700% following airstrikes

https://www.elliptic.co/blog/iranian-cryptoasset-outflows-surge-700-percent-following-attacks
1•giuliomagnifico•1m ago•0 comments

Attempting to detect smart glasses nearby and warn you

https://blog.adafruit.com/2026/03/02/attempting-to-detect-smart-glasses-nearby-and-warn-you/
1•EvgeniyZh•9m ago•0 comments

Show HN: Instbyte – Self-hosted LAN sharing tool, run with npx, no cloud

https://github.com/mohitgauniyal/instbyte
1•mohitgauniyal•9m ago•1 comments

Feynman's War: Modelling Weapons, Modelling Nature (1986) [pdf]

https://gwern.net/doc/science/physics/1998-galison.pdf
1•nill0•11m ago•0 comments

The Download: protesting AI, and what's floating in space

https://www.technologyreview.com/2026/03/02/1133811/the-download-protesting-ai-and-whats-floating...
1•joozio•14m ago•0 comments

LeRobot: An Open-Source Library for End-to-End Robot Learning

https://arxiv.org/abs/2602.22818
2•nill0•15m ago•0 comments

PDF Tools

https://www.pdffixnow.com
1•instahotstar•20m ago•0 comments

Comfy.org

https://blog.comfy.org/
1•VanessaMGSA•20m ago•0 comments

Show HN: My OpenClaw knows what it did a week ago. Thanks to "hmem"-MCP

1•Bumblebiber•23m ago•0 comments

Africa Imported Europe's Worst Idea

https://magatte.substack.com/p/how-africa-imported-europes-worst
2•EvgeniyZh•24m ago•0 comments

Anthropic's Feud with Pentagon Earns It Fans Amid the Blowback

https://www.wsj.com/tech/ai/anthropics-feud-with-pentagon-earns-it-fans-amid-the-blowback-f7e2bb83
2•JumpCrisscross•25m ago•0 comments

KlongPy: Automatic Differentiation

http://www.klongpy.org/torch_backend/
1•tosh•26m ago•0 comments

Sam Altman: We have been working with the Dow to make our principles clear

https://twitter.com/i/status/2028640354912923739
2•matthieu_bl•26m ago•0 comments

How well do you know Claude Code?

https://claude-code.vercel.app/test
2•Krishnaa_•28m ago•0 comments

When "More" Makes the System Worse

https://kb-it.net/when_more_makes_the_system_worse/
2•better-it•30m ago•1 comments

Merrilin – We built an app to read books

https://tech.stonecharioteer.com/posts/2026/merrilin/
1•two_poles_here•30m ago•0 comments

Sandboxing Like a Pro in the Age of GasTown

https://github.com/avkcode/firecracker-sandbox
1•KyleVlaros•30m ago•0 comments

How to Recover Stolen Cryptocurrency and USDT

https://www.autopsymainnetsolutions.com
1•SAMUELluck•32m ago•0 comments

Another round of reporting on feed readers

https://rachelbythebay.com/w/2026/02/23/readers/
1•theshrike79•34m ago•0 comments

The Worst Language Won

https://theoryvc.com/blog-posts/the-worst-language-won
2•taubek•36m ago•0 comments

Arm's Cortex X925: Reaching Desktop Performance

https://chipsandcheese.com/p/arms-cortex-x925-reaching-desktop
6•ingve•43m ago•0 comments

Odd Lots, some guests are more perfect than others

https://networked.substack.com/p/on-odd-lots-some-guests-are-more
1•jaypinho•45m ago•1 comments

glFTPD

https://glftpd.io/
1•metadat•47m ago•0 comments

The Hacker Times

https://the-hacker-times.examples.workers.dev
1•fayazara•48m ago•1 comments

Fundamentals for Using Hyperspectral and Thermal Earth Observation Data (Day 1) [video]

https://www.youtube.com/watch?v=O6uSkvT8Zr0
1•marklit•50m ago•0 comments

HyperCard Changed Everything [video]

https://www.youtube.com/watch?v=hxHkNToXga8
1•adfm•50m ago•0 comments

Latest ToS update includes class action waiver and forced arbitration

https://github.com/zed-industries/zed/issues/50568
2•database64128•53m ago•0 comments

Myrient will shut down on 31 March 2026. Download any content you find important

https://myrient.erista.me
1•chaifeng•57m ago•0 comments

Neural-Temporal Compression – A State-Persistence Framework

https://github.com/andresuarus10-byte/memory-engine
1•KaelyrAT13•59m ago•2 comments

Show HN: A Calculator for Garden Horizons

https://gardenhorizons.app/
1•hugh1st•1h ago•0 comments