frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•7mo ago

Comments

kemotep•7mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Curiouser and curiouser: a riddle at the Alice detector

https://www.symmetrymagazine.org/article/curiouser-and-curiouser-a-riddle-at-the-alice-detector?l...
1•elashri•1m ago•0 comments

Typeframe PX-88: Raspberry Pi-powered CyberDeck inspired by a 1980s portable PC

https://liliputing.com/typeframe-px-88-is-a-raspberry-pi-powered-cyberdeck-inspired-by-a-portable...
1•PaulHoule•3m ago•0 comments

Michigan man dies of rabies after receiving kidney from infected donor

https://www.foxnews.com/health/michigan-man-dies-rabies-after-receiving-kidney-from-infected-dono...
1•mudil•3m ago•0 comments

Sandia Supercomputer Built on NextSilicon's Maverick-2 Accelerators

https://www.hpcwire.com/off-the-wire/sandia-unveils-spectra-supercomputer-built-on-nextsilicons-m...
1•eyalitki•3m ago•0 comments

Rust-script – Run Rust files and expressions as scripts

https://rust-script.org/
1•gjvc•4m ago•0 comments

Balanced Ternary Transformers: 93.8% Energy Reduction Using 1965 Soviet Research

https://zenodo.org/records/17875182
2•ZaneHam•6m ago•1 comments

Show HN: RAG-TUI – Visual chunking debugger for RAG pipelines in the terminal

https://pypi.org/project/rag-tui/
1•rasinmuhammed•8m ago•0 comments

Show HN: DskDitto

https://github.com/jdefrancesco/dskDitto
1•jdefr89•10m ago•0 comments

LLM Council – Your Local Multi-Model AI Advisory Board

https://github.com/karpathy/llm-council
1•the-mitr•11m ago•0 comments

SpaceX to Pursue 2026 IPO Raising Far Above $30B

https://www.bloomberg.com/news/articles/2025-12-09/spacex-said-to-pursue-2026-ipo-raising-far-abo...
1•donsupreme•13m ago•0 comments

NPM Revokes Classic Tokens, as OpenJS Warns Maintainers About OIDC Gaps

https://socket.dev/blog/npm-revokes-classic-tokens
1•feross•13m ago•0 comments

Show HN: DskDitto

1•jdefr89•17m ago•0 comments

Pet Artist

https://petartist.ai/en
1•NikkiWang•18m ago•1 comments

Show HN: What Paid Directories Charge in 2025

https://directoryideas.ai/pricing-benchmark-study
1•tejas3732•33m ago•0 comments

Cybernetic Methods in Chemistry and Chemical Engineering (1976)

https://archive.org/details/v.-kafarov-cybernetic-methods-in-chemistry-and-chemical-engineering-m...
2•the-mitr•33m ago•0 comments

The Autobiography of JGB

https://www.newyorker.com/magazine/2009/05/11/the-autobiography-of-j-g-b
1•jdkee•34m ago•2 comments

Do Not Optimize Away

https://matklad.github.io/2025/12/09/do-not-optimize-away.html
1•todsacerdoti•34m ago•0 comments

Elon: Satellites best way to scale AI within 4 years

https://twitter.com/elonmusk/status/1997706687155720229
1•lquist•51m ago•1 comments

Orchids – The Vibe Coding IDE

https://www.orchids.app/
2•doppp•59m ago•2 comments

Nvidia Isn't Enron – So What Is It?

https://www.wheresyoured.at/nvidia-isnt-enron-so-what-is-it/
1•s3graham•1h ago•0 comments

Gmail emoji reactions will be enabled by default starting Feb

https://www.prettyfwd.com/t/XOR4SAN3R1qitLNl5hHwNg/
1•Alex3917•1h ago•0 comments

Meesho Goes Public

https://www.ycombinator.com/blog/meesho-goes-public/
3•todsacerdoti•1h ago•1 comments

Dependable C

https://dependablec.org/
2•RossBencina•1h ago•0 comments

Collective Governance for AI: Points of Intervention

https://metagov.org/cg-ai/
1•ntnsndr•1h ago•0 comments

Linus Torvalds is 'a believer' in using AI to maintain code

https://www.zdnet.com/article/linus-torvalds-ai-tool-maintaining-linux-code/
3•CrankyBear•1h ago•2 comments

UK agrees higher drug prices to secure zero-tariff deal with US

https://www.chemistryworld.com/news/uk-agrees-higher-drug-prices-to-secure-zero-tariff-deal-with-...
2•geox•1h ago•0 comments

Most Frequent UI Errors App Developers Make

https://makeincoimbatore.substack.com/p/the-most-frequent-ui-errors-app-developers
1•swathid•1h ago•0 comments

Butterick's Practical Typography

https://practicaltypography.com/
1•cardamomo•1h ago•0 comments

Show HN: Built some privacy tools

https://privsen.com/
1•privsen•1h ago•0 comments

For App Developers: How to Identify and Fix Common Vulnerabilities

https://makeincoimbatore.substack.com/p/for-app-developers-how-to-identify
1•swathid•1h ago•0 comments