frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Renderformer V2 (Full neural rendering)

https://renderformer.github.io/v2/
2•E-Reverance•7m ago•0 comments

Use of 'Reasonable' in Gun Control Advocacy

https://firearmsresearchcenter.org/working_papers/use-of-reasonable-in-gun-control-advocacy/
2•delschlangen•7m ago•0 comments

Mcptestkit

https://pypi.org/project/mcp-testkit/
2•opiniateddev•13m ago•0 comments

Fast Unicode (UTF-8) validation with autovectorization

https://nitely.github.io/2026/08/30/fast-unicode-utf-8-validation.html
1•nitely•25m ago•0 comments

I ran out of AI tokens in one app while holding unused tokens in another

1•nextma•29m ago•1 comments

40k Pounds of Pabst Blue Ribbon Beer Reported Stolen in California

https://www.nytimes.com/2026/08/29/business/pabst-beer-truck-stolen-california.html
1•ChrisArchitect•29m ago•0 comments

Tell HN: STOP making Vibe Slop websites that LAG on my MBP and workstation

2•moomoo11•30m ago•1 comments

Establishing the United States Space Academy – The White House

https://www.whitehouse.gov/presidential-actions/2026/08/establishing-the-united-states-space-acad...
3•rbanffy•32m ago•1 comments

Dancing Bot (Stepmania)

https://dominickp.github.io/dancing-bot/
2•dominick-cc•33m ago•2 comments

How Wingman is able to be client agnostic

https://docs.wingman.actor/concepts/clients/
1•ChaseRensberger•33m ago•1 comments

California lawmakers unanimously pass Linux exemption from age-verification law

https://www.tomshardware.com/software/linux/california-lawmakers-unanimously-pass-linux-exemption...
3•shscs911•34m ago•0 comments

You have to beat the models at something

https://www.seangoedecke.com/you-have-to-beat-the-models-at-something/
4•sam_bristow•38m ago•0 comments

There's no such thing as Just a Tool

https://deadsimpletech.com/blog/no-such-thing-as-just-a-tool
2•cratermoon•42m ago•0 comments

Ask HN: Hard Mode for LLMs

1•Harlekuin•44m ago•0 comments

Show HN: Memnest, local-first memory shared by pi, Claude Code and Codex

https://github.com/Blue-B/memnest
1•blue-b•45m ago•0 comments

China's AI Revolution and the Ideology of Xi Jinping

https://kevinrudd.com/media/anu-centre-for-china-in-the-world-annual-lecture-2026
1•verdverm•47m ago•1 comments

The Engineer as a Learning-System Builder

https://eug.github.io/posts/engineer-as-learning-system-builder.html
2•eugf_•52m ago•0 comments

World's first battery-powered self-unloading bulk carrier starts in Australia

https://www.bunkerindex.com/articles/article.php?a=23396&h=worlds-first-battery-powered-self-unlo...
3•thunderbong•53m ago•0 comments

LibreOffice 28.8

https://en.libre-office.fr/article.php/libreoffice-26-8-release-key-features-you-need-to-know
2•linuxkernal•55m ago•0 comments

Best AI Quiz Generator?

https://quizroom.ai
1•taimurkazmi•1h ago•1 comments

No Country for Mediocre Mathematicians

https://garvvee.substack.com/p/no-country-for-mediocre-mathematicians
6•reasonableklout•1h ago•2 comments

Popular code generator for TanStack Query hit by supply chain worm

https://www.aikido.dev/blog/popular-code-generator-for-tanstack-query-hit-by-supply-chain-worm
4•lbw1215•1h ago•0 comments

Algorithmic Rent-Pricing Litigation Expands Under New State and Local Laws

https://www.morganlewis.com/pubs/2026/08/algorithmic-rent-pricing-litigation-expands-under-new-st...
10•toomuchtodo•1h ago•1 comments

Show HN: TypeGPU Realtime Physics Sandbox

https://typegpu-sandbox.pages.dev
1•theRealestAEP•1h ago•0 comments

SkillRepo – Skillsets: Skill Governance for Teams

https://skillrepo.dev/blog/introducing-skillsets
2•atxpace•1h ago•0 comments

Is SQLite Having a Moment?

https://en.wikipedia.org/wiki/SQLite
1•diwash007•1h ago•0 comments

Meta Project OT plan to replace employees with AI agents

https://www.thestreet.com/technology/mark-zuckerberg-shocking-message-meta-employee-layoffs-artif...
10•elboru•1h ago•5 comments

Incorrect geo location for some Cloudflare WARP users – Cloudflare Status

https://www.cloudflarestatus.com/incidents/9g65dxfbcjln
1•kyisaiah47•1h ago•0 comments

Postgres isn't slow. Your storage is

https://clickhouse.com/blog/posette-talk-recap-postgres-isnt-slow-your-storage-is
4•gpavanb•1h ago•0 comments

President Trump Signs Executive Order to Create US Space Academy

https://www.nasa.gov/news-release/president-trump-signs-executive-order-to-create-us-space-academy/
6•efavdb•2h ago•3 comments
Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.