frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

We accidentally built an oscillating policy engine

https://blog.bridgexapi.io/we-accidentally-built-an-oscillating-policy-engine
1•Bridgexapi•53s ago•0 comments

OpenMLS has undergone a security audit, funded by the Sovereign Tech Agency

https://blog.phnx.im/openmls-independent-security-audit/
3•cityroler•1m ago•0 comments

U.S. to send Americans exposed to Ebola to Kenya quarantine facility

https://www.washingtonpost.com/health/2026/05/27/us-send-americans-exposed-ebola-kenya-quarantine...
1•Anon84•1m ago•0 comments

Show HN: A tool to debug complex Stripe interactions (built with Claude's help)

https://github.com/progapandist/stripeek
2•progapandist•2m ago•0 comments

Sandboxing for dummies: Process isolation, seccomp and writing good policies

https://renato.boo/blog/2026/05/11/sandboxing-linux-seccomp
1•renatoboo•2m ago•0 comments

Ask HN: How did you find your current job?

1•chistev•5m ago•0 comments

Minimal, gimmick-free EDC knives built for actual daily use

https://www.paragon-knives.com/
1•bgzlsxaz•6m ago•0 comments

Ferrari's electric car: divisiveness is the point

https://economist.com/business/2026/05/27/ferraris-electric-car-divisiveness-is-the-point
1•andsoitis•7m ago•0 comments

It's surprisingly hard to tell if someone's drowning, so we made you a guide

https://www.popsci.com/identify-prevent-drowning/
1•chistev•9m ago•0 comments

Marque – Domain Registrar on the AT Protocol

https://marque.at
1•scanash00•15m ago•0 comments

A New Register Allocator for ZJIT

https://railsatscale.com/2026-05-27-a-new-register-allocator-for-zjit/
1•thunderbong•16m ago•0 comments

Show HN: I packaged a Python AI agent and Vue dashboard into one Electron app

https://github.com/sir1st/hermes-desktop
1•sir1st•16m ago•0 comments

IBM commits $5B to secure open-source software

https://www.reuters.com/legal/transactional/ibm-commits-5-billion-secure-open-source-software-202...
2•giuliomagnifico•21m ago•0 comments

We need to own our computing experience

https://andregarzia.com/2026/05/we-need-to-own-our-computing-experience.html
1•soapdog•21m ago•0 comments

The Anatomy of an LLM

https://www.royvanrijn.com/anatomy-of-an-llm/
2•redcodenl•24m ago•2 comments

You can now use your Gmail account in Proton Mail

https://proton.me/blog/proton-mail-connect-gmail
3•berlianta•24m ago•1 comments

Show HN: Shaderbang – Shebang for Shaders

https://github.com/astefanutti/shaderbang
2•astefanutti•26m ago•0 comments

Machine Media: The Death of the Open Web

https://ipullrank.com/machine-media
1•iamacyborg•30m ago•0 comments

Midday – Open Source Invoicing, Time Tracking, File Reconciliation, Storage, etc

https://github.com/midday-ai/midday
1•peter_d_sherman•31m ago•0 comments

Motorola stops its phones from hijacking the Amazon app, which was 'unintended'

https://9to5google.com/2026/05/27/motorola-amazon-app-unintended/
3•mslusarz•33m ago•1 comments

Money Printer Pro – Open-source AI content generator

https://github.com/office233/MoneyPrinterPro
1•office233•35m ago•0 comments

Claude Opus 4.8 coming today?

https://twitter.com/synthwavedd/status/2059931370009272802
1•rebekkamikkoa•37m ago•1 comments

Show HN: Electrical Grid Mapping Launchpad

https://MapYourGrid.org/map-it/
2•andreashd11•42m ago•1 comments

DeepSeek-OCR Visualized

https://medium.com/advanced-deep-learning/deepseek-ocr-fully-visualised-843e2ba03976
1•coarchitect•42m ago•2 comments

Show HN: Generate Claude Code Workflows using Spec Driven Development approach

2•sermakarevich•44m ago•0 comments

Understand Vision Language Models

https://medium.com/advanced-deep-learning/how-ai-sees-and-reads-visualising-vision-language-model...
1•coarchitect•46m ago•1 comments

Show HN: AT4K Launcher - Apple TV inspired Launcher for Android TVs

https://at4klauncher.com
2•avadhesh18•46m ago•1 comments

Racket v9.2 is now available

https://blog.racket-lang.org/2026/05/racket-v9-2.html
3•spdegabrielle•46m ago•1 comments

Dirk and Linus discuss AI and kernel development

https://lwn.net/SubscriberLink/1073761/289a4e5513688987/
2•chmaynard•48m ago•0 comments

The lost Doves Type: A Thames mystery solved

https://www.londonmuseum.org.uk/blog/doves-type-thames-mystery-mudlarking/
1•ColinWright•49m ago•0 comments