frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•12mo ago

Comments

kemotep•12mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

A Milestone in Formalization: The Sphere Packing Problem in Dimension 8

https://www.alphaxiv.org/abs/2604.23468
1•measurablefunc•11s ago•0 comments

Proxies, Sandboxes and Agent Security

https://www.gouthamve.dev/proxies-sandboxes-and-agent-security/
1•gouthamve•1m ago•0 comments

My Login Shell in Assembly

https://isene.org/2026/04/Bare.html
1•birdculture•2m ago•0 comments

VibeBench: Measuring 1k Engineers' Opinions of New Models

https://vibebench.standardagents.ai/
3•jpschroeder•6m ago•0 comments

From spaghetti to main bus: refactoring an AI agent orchestrator with Elm

https://blog.mariohayashi.com/p/the-factory-must-grow-part-ii-from
1•mhay•7m ago•0 comments

Show HN: 49Agents – 2D Canvas IDE for Orchestrating Agents, Repos, Issues

https://github.com/49Agents/49Agents
1•alpadurza•9m ago•0 comments

For SF's public defenders, resistance is the new black

https://sfstandard.com/2026/04/27/public-defenders-wear-all-black-protest/
1•iancmceachern•10m ago•0 comments

The lamps you're not allowed to have. Exploring the Dubai lamps (2021) [video]

https://www.youtube.com/watch?v=klaJqofCsu4
2•bb88•10m ago•0 comments

Joby flies first point-to-point air taxi flight tests in New York

https://www.reuters.com/business/aerospace-defense/joby-flies-first-point-to-point-air-taxi-fligh...
1•canucker2016•11m ago•0 comments

An open-source platform to auto-update agent skills and discover fresh sources

https://www.loooop.dev/
1•kl01•15m ago•0 comments

Redmine

https://www.redmine.org/
1•tamnd•16m ago•0 comments

A persistent Unix-like ESP8266 system with more that 70 console commands

https://github.com/hery-torrado/KernelESP
2•herytorrado•21m ago•1 comments

Client side search and recommendation with TurboQuant

https://h3manth.com/ai/cinematch/
1•init0•23m ago•0 comments

There's a Good Reason You Can't Concentrate

https://www.nytimes.com/2026/03/27/opinion/technology-mental-fitness-cognitive.html
1•philip1209•24m ago•0 comments

The Secret Group Chats Fueling MAGA's Messaging Machine

https://slate.com/technology/2026/04/trump-ballroom-ashley-st-clair-maga.html
3•JojoFatsani•24m ago•0 comments

Victory in FOIA Against Twelve South for PlugBug 120W Electrical Info

https://archive.org/details/pb120-us
1•birdculture•27m ago•0 comments

What Are OPEC+'s Fiscal Breakeven Oil Prices Telling Us?

https://economics.bmo.com/en/publications/detail/141134d9-5322-4b04-bf49-2c3e6088115a/
1•JumpCrisscross•29m ago•0 comments

Canada govt plans crypto ATM ban to stop scammers from defrauding Canadians

https://www.cbc.ca/news/canada/toronto/canada-crypto-atm-ban-scammers-9.7180642
2•canucker2016•34m ago•1 comments

The Revealing Summary Reversal in LULAC

https://www.stevevladeck.com/p/223-the-revealing-summary-reversal
2•hn_acker•35m ago•1 comments

Claude-multiprofile: run multiple Claude accounts side by side on macOS

https://github.com/jmdarre-v/claude-multiprofile
3•jmd7•37m ago•0 comments

Asimov, an open source tsla humanoid

https://github.com/asimovinc/asimov-v1
3•ElasticBottle•39m ago•0 comments

SubmitYourWork – Submit your startup to directories from one place

https://github.com/Sketchjar/submityourwork
2•gcsydney•39m ago•0 comments

Couples Wanted to Have Children. Rising Costs Are Stopping Them

https://www.nytimes.com/2026/04/26/business/children-rising-costs.html
2•lando2319•43m ago•1 comments

Ask HN: Can we just call them "Harness Gloves"?..and an App Store model?

2•lowoxidizer•43m ago•0 comments

The 3-character kernel patch that tamed the OOM killer for Postgres

https://www.ubicloud.com/blog/postgresql-and-the-oom-killer-why-we-use-strict-memory-overcommit
3•mustpax•43m ago•0 comments

Super Zsnes: GPU Powered SNES Emulation

https://www.youtube.com/watch?v=r5twUkvYFpA
4•kjeetgill•44m ago•0 comments

Show HN: I built another to do list. But it does a lot

https://apps.apple.com/us/app/rotation-list-shared-to-do/id6758746324
2•toddh•45m ago•0 comments

Which (tech) companies have the best work life balance?

3•philmcp•45m ago•0 comments

Show HN: InterviewDen – Free voice AI mock interviews for SWE, IB, quant, more

https://theinterviewden.com/
2•psonthalia•45m ago•0 comments

I just added every Pulsing Aura card to the PTCGP database I maintain

https://pocketcards.net/database
2•bat0x01•45m ago•0 comments