frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

How AI Talks People Out of Conspiracy Theories–and What We Can Learn from That

https://www.wsj.com/tech/ai/ai-debunks-conspiracy-theories-92eff2c5
1•MilnerRoute•3m ago•0 comments

Honopinion

https://honopinion.com
1•mroshani20•7m ago•0 comments

We Built Secure, Scalable Agent Sandbox Infrastructure

https://twitter.com/larsencc/status/2027225210412470668
1•gmays•9m ago•0 comments

Mvm – a fast virtual machine for Go

https://mvm.sh/
1•birdculture•11m ago•0 comments

Teaching Codex to Test a Voice-First Calendar App

https://www.elicited.blog/posts/teaching-codex-to-test-a-voice-first-calendar
1•justanotheratom•13m ago•1 comments

What were your favorite classic iPod games?

1•wompapumpum•15m ago•0 comments

'What Matters Most'–Google Is Changing Your Gmail Inbox

https://www.forbes.com/sites/zakdoffman/2026/05/23/what-matters-most-google-is-changing-your-gmai...
1•healsdata•23m ago•0 comments

Lessons I Learned from Creating Searx

https://hister.org/posts/lessons-i-learned-from-creating-searx
1•xosc•25m ago•0 comments

How Google's Beta Tester Requirement Created a Fiverr Grey Market

https://danunparsed.com/p/googles-beta-tester-requirement
3•sambellll•33m ago•0 comments

The Black Hole Scientists Say Is Growing Too Fast

https://substack.com/profile/512907875-hamza-ashkar/note/c-264627457
2•hamzaashkar•34m ago•0 comments

Agent evals should feel like real work

https://www.zohaib.cc/blog/agent-evals
1•zed_labs_dev•54m ago•0 comments

Verifying a Caliptra Boot-FSM Bug with Mununu

https://marianocerrutti.substack.com/p/verifying-a-caliptra-boot-fsm-bug
1•hasheddan•54m ago•0 comments

The Densest (Urban) Environment in the World

https://oldurbanist.blogspot.com/2011/09/densest-urban-environment-in-world.html
3•Neuronaut•58m ago•1 comments

Poll: Test

1•sillysaurusx•1h ago•0 comments

The Green Side of the Lua

https://arxiv.org/abs/2601.16670
2•radiator•1h ago•0 comments

Star Citizen game has reached $1B in funding

https://robertsspaceindustries.com/en/funding-goals
6•speckx•1h ago•0 comments

Show HN: JavaScript Crossword – a crossword where the clue = eval(answer)

https://lyra.horse/fun/jscrossword/
1•rebane2001•1h ago•0 comments

No Asterisk Products Manifesto: hardware that works when the servers go down

https://noasteriskproducts.org/
2•brooklyntom•1h ago•0 comments

Built a small PR guardrail for token bloat, worth maintaining?

https://github.com/unloopedmido/contextlevy
1•nonlooped•1h ago•0 comments

Test

1•sillysaurusx•1h ago•0 comments

Cracked in under a minute: (nearly) every other password

https://www.kaspersky.com/blog/passwords-hacking-research-2026/55743/
1•gnabgib•1h ago•1 comments

The Enhanced Games: It's like the Olympics – except steroids are allowed

https://www.bbc.com/news/articles/cedpz1zqp8po
3•busymom0•1h ago•2 comments

Librarian: Tidy Up the Arcane Library

https://store.steampowered.com/app/4197610/Librarian_Tidy_Up_the_Arcane_Library/
2•doener•1h ago•0 comments

What Are Atoms Made Of?

https://johncarlosbaez.wordpress.com/2026/05/24/what-are-atoms-made-of/
2•mathgenius•1h ago•0 comments

Show HN: Tuie - A rich, performant TUI library for rust

https://github.com/jake-stewart/tuie
1•vim-god•1h ago•0 comments

TID: Linux kernelmodule–flushes CPU cache after wiping sensitive data CLFLUSHOPT

https://github.com/ahmaaaaadbntaaaaa-byte/TID-The-Instant-Destroyer
1•TID_Ahmad•1h ago•0 comments

Anthropic and OpenAI race to embed engineers inside Wall Street workflows

https://thenewstack.io/anthropic-openai-wall-street-ai-agents-developers/
1•dr_dshiv•1h ago•0 comments

What to know about the AI models that are jolting Washington

https://www.politico.com/news/2026/05/24/anthropic-openai-mythos-what-to-know-00934668
2•TMWNN•1h ago•1 comments

AI for Design Needs Solving

https://freedium-mirror.cfd/https://medium.com/@mini.1409/ai-for-design-needs-solving-db3f11af77d4
1•vinayak-shukla•1h ago•0 comments

AI in journalism: Live tracker of scandals and mistakes

https://pressgazette.co.uk/publishers/digital-journalism/ai-journalism-mistakes/
2•gnabgib•1h ago•0 comments