frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Using AI for Just 10 Minutes Might Make You Lazy and Dumb, Study Shows

https://www.wired.com/story/using-ai-negative-impact-thinking-problem-solving-study/
1•gnabgib•33s ago•0 comments

Show HN: WordPress WebSocket Relay in Rust with Yjs CRDT Provider for WP 7.0

https://wpsignal.io/
1•jaredrethman•1m ago•0 comments

Show HN: HeatSpectra: Realtime 3D Surface Heat Simulation

https://github.com/tsun3doku/HeatSpectra
1•tsun3doku•6m ago•0 comments

An Oura ring starting at just $1 Welcome to Churu

https://churu.org
1•reieicucv•7m ago•0 comments

Roche to Buy PathAI for Up to $1.05B to Bolster AI Diagnostics Tools

https://www.wsj.com/business/deals/roche-to-buy-pathai-for-up-to-1-05-billion-to-bolster-ai-diagn...
1•SaaSasaurus•8m ago•0 comments

AniTroves – An anime database with a custom LLM-based discovery hub

1•anitroves•11m ago•0 comments

YouTube aspect ratios – no way to fix it?

1•mr-pink•11m ago•1 comments

Show HN: Agentctl, a local control plane for coding agents

https://github.com/chocks/agentctl
1•chocks•14m ago•0 comments

I made a simple, free family tree app that handled my 300 person, 5 gen. family

https://www.familytreeiq.com
1•mknweb•14m ago•1 comments

Upper bound for AI output is based on your taste/exposure

1•yehiaabdelm•23m ago•0 comments

Best Buy mandating four days in office for headquarters employees

https://www.startribune.com/best-buy-hybrid-four-days-change-shift-mandate-in-office/601828733
2•bjhess•23m ago•1 comments

I recently started a small experimental project recreating Star Fox 64

https://foxremake.com/star-fox-64-remake/
2•951560368•31m ago•3 comments

Proposed Revised Mailing Standards for Firearms

https://www.federalregister.gov/documents/2026/04/02/2026-06376/revised-mailing-standards-for-fir...
2•petethomas•33m ago•0 comments

AI Contributions to CPAN: The Copyright Question

https://blogs.perl.org/users/todd_rinaldo/2026/04/ai-contributions-to-cpan-the-copyright-question...
2•DASD•33m ago•0 comments

Mathematics Subject Classification (2020)

https://mathscinet.ams.org/mathscinet/msc/msc2020.html
2•nill0•38m ago•0 comments

Show HN: NyaayWatch – Observability layer for the Indian judiciary

https://nyaaywatch.in
2•Rudraksh06•39m ago•0 comments

The Privacy of Apple Location Services and Analytics

https://duti.dev/randoms/wip-location-services/
5•Cider9986•41m ago•0 comments

Jakarta airport's official site blocks international visitors, so I built my own

https://blog.terrydjony.com/i-built-a-better-cgk-airport-website/
2•terryds•41m ago•0 comments

A Dangerous New Attack on Press Freedom

https://www.theatlantic.com/ideas/2026/05/kash-patel-fitzpatrick-fbi-investigation/687077/
9•petethomas•56m ago•3 comments

Net May 15 Starship • Flight 12

https://spaceflightnow.com/launch-schedule/
3•bookmtn•56m ago•1 comments

AWS EC2 outage in use1-az4 (us-east-1)

https://health.aws.amazon.com/health/status?t=2026-05-07
18•philip1209•58m ago•5 comments

6 years of CS2 skin market data, indexed S&P-style (open methodology)

https://skintrackers.com/en
1•Jorgincs•1h ago•2 comments

The Long Journey from the Strait of Hormuz to the Gas Tank

https://www.nytimes.com/interactive/2026/05/07/world/middleeast/oil-tanker-strait-hormuz-iran-war...
3•voxadam•1h ago•1 comments

Yarbo Nat in My Backyard

https://github.com/Bin4ry/yarbo-nat-in-my-back-yard
3•greedo•1h ago•0 comments

UBC, SFU among universities affected by Canvas software cyber breach

https://www.cbc.ca/news/canada/british-columbia/ubc-sfu-canvas-cyber-breach-9.7191972
1•uladzislau•1h ago•0 comments

GPT-5.5 Price Increase: What It Costs

https://openrouter.ai/announcements/gpt55-cost-analysis
2•gmays•1h ago•0 comments

OpenAI end of lifes fine-tuning

https://developers.openai.com/api/docs/deprecations
2•dandiep•1h ago•1 comments

Pentagon CTO demonstrates Palantir's Maven system, used for military operations [video]

https://www.youtube.com/watch?v=Q5uVckUvGcQ
4•LostMyLogin•1h ago•0 comments

Netflix tests its own AI-powered voice search

https://www.lowpass.cc/p/ask-netflix-ai-voice-search
1•andsoitis•1h ago•0 comments

The IDE Should Become an Operating System for AI

https://avkcode.github.io/blog/ide-operating-system-ai.html
2•akrylov•1h ago•0 comments