frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Why SaaS companies are scared Takes ODE 15 mins to do what takes them 6 months

https://www.llewellynsystems.com
1•LLSODE•16s ago•0 comments

Claude Opus 4.6 Fast Mode: 2.5x Faster, 6x More Expensive

https://www.marc0.dev/en/blog/claude-opus-4-6-fast-mode-pricing-6x-cost-breakdown-1770499078106
1•mefengl•7m ago•0 comments

Built an open-source tool that lets you deploy containers to your VPS via MCP

https://github.com/ddalcu/mcp-deploy
1•ddalcu•8m ago•1 comments

CDC: Why Decompression Is Worth the Complexity

https://wael.nasreddine.com/nixos/cdc-why-decompression-worth-co
1•kalbasit•14m ago•1 comments

Show HN: Brood, a reference-first AI image editor for macOS

https://github.com/kevinshowkat/brood
1•latentcraft•15m ago•1 comments

Amazon's cloud unit hit by outage involving AI tools in December

https://www.reuters.com/business/retail-consumer/amazons-cloud-unit-hit-by-least-two-outages-invo...
1•1vuio0pswjnm7•18m ago•0 comments

Show HN: Clawscan – Open-source security scanner for OpenClaw AI agents

https://github.com/osmankidwai-bot/clawscan
1•clawscan•19m ago•0 comments

A chat-style site for Hacker News trends

https://github.com/1997roylee/yc-chat
1•1997roylee•24m ago•1 comments

Forgelink Is Here

1•frostfrazer•24m ago•0 comments

Show HN: HashTrade – Open-source LLM trading agent with episodic memory

https://github.com/mertozbas/hashtrade
1•mertozbas•26m ago•0 comments

I just started a Substack where I talk about building Midrop

https://klaudjo.substack.com/subscribe
1•Klaudjo_shkurta•28m ago•0 comments

Show HN: Threatmodeling Tool to outgrow spreadsheets, word and MS-TMT

https://www.threatmodeling-tool.com/blog
1•Rana_KV•30m ago•0 comments

Amazfit T-Rex Ultra 2 review:flagship battery life at fraction of Garmin's price

https://www.t3.com/active/fitness-trackers/amazfit-t-rex-ultra-2-review
1•teleforce•31m ago•0 comments

The Longevity Scam

https://www.theatlantic.com/health/2026/02/longevity-medicine-profit-oversold/686049/
1•JumpCrisscross•32m ago•0 comments

Show HN: Random Topic Generator – Impromptu Speech Topics and Timer

https://randomtopicgenerator.net
1•QingWu•33m ago•0 comments

Reality's Moat

https://davidbeyer.xyz/writing/realitys-moat
1•vaeyshl•35m ago•1 comments

NASA's Artemis II rocket experienced interrupted flow of helium

https://www.nasa.gov/blogs/missions/2026/02/21/nasa-troubleshooting-artemis-ii-rocket-upper-stage...
2•logifail•43m ago•1 comments

DHS suspends TSA PreCheck and Global Entry airport security programs

https://apnews.com/article/homeland-security-tsa-precheck-global-entry-dc1d2ccd913a74fa2c8b91dad3...
4•JumpCrisscross•47m ago•0 comments

Ask HN: Why doesn't HN have a rec algorithm?

2•sujayk_33•50m ago•2 comments

No LLM, No training data, No cloud – Engine that understands architecture

1•twoelf•53m ago•2 comments

WebMCP: A Browser-Native Execution Model for AI Agents

https://insforge.dev/blog/webmcp-browser-native-execution-model-for-ai-agents
1•astro_09•54m ago•0 comments

Mini Claw Code – Write your own mini coding agent

https://github.com/odysa/mini-claw-code
2•agentforce•58m ago•0 comments

Show HN: X-Ray – Filter your X (Twitter) timeline by country

https://chromewebstore.google.com/detail/x-ray-block-tweets-by-rea/pmjfhfleckpdbhfblgeiihihddlbifaf
1•batudotpy•58m ago•0 comments

Estonias Tiger Leap: the schools project that wired a nation for the digital age

https://estonianworld.com/technology/estonias-tiger-leap-the-schools-project-that-wired-a-nation-...
2•atlasunshrugged•59m ago•0 comments

DHS pausing TSA PreCheck, Global Entry programs amid funding lapse

https://www.nbcnews.com/news/us-news/dhs-pausing-tsa-precheck-global-entry-programs-funding-lapse...
5•LopRabbit•1h ago•0 comments

Microsoft throws spox under the bus in ICC email flap

https://www.theregister.com/2026/02/18/microsoft_asks_uk_parliament_to_correct_record/
5•abdelhousni•1h ago•0 comments

U.S. Cannot Legally Impose Tariffs Using Section 122 of the Trade Act of 1974

https://ielp.worldtradelaw.net/2026/01/guest-post-president-trump-cannot-legally-impose-tariffs-u...
4•JumpCrisscross•1h ago•0 comments

Show HN: Fan Meter – A movie quiz game where you guess films from frames

https://fanmeter.in
2•raahelb•1h ago•3 comments

Optimize_anything: A Universal API for Optimizing Any Text Parameter

https://gepa-ai.github.io/gepa/blog/2026/02/18/introducing-optimize-anything/
1•LakshyAAAgrawal•1h ago•1 comments

So Claude's stealing our business secrets, right?

6•arm32•1h ago•4 comments