frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•10mo ago

Comments

kemotep•10mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

Tech Has Never Caused a Job Apocalypse. Don't Bet on It Now

https://www.wsj.com/economy/jobs/tech-has-never-caused-a-job-apocalypse-dont-bet-on-it-now-d192b579
1•johntfella•40s ago•0 comments

Ask HN: How do you enforce guardrails on Claude agents taking real actions?

1•jamiecode•2m ago•0 comments

Metamorphic Testing for Infrastructure-as-Code Engines [pdf]

https://programming-group.com/assets/pdf/papers/2026_Metamorphic-Testing-for-IaC-Engines.pdf
2•matt_d•7m ago•0 comments

Tripling an LLM's ARC-AGI-2 score with code evolution

https://imbue.com/research/2026-02-27-arc-agi-2-evolution/
6•danielmewes•8m ago•0 comments

AdaptiveCpp's new Metal backend to support CUDA dialect on Apple GPUs

https://github.com/AdaptiveCpp/AdaptiveCpp/pull/1983
2•puschkinfr•12m ago•0 comments

New 'Mars GPS' lets Perseverance pinpoint its location within 25 centimeters

https://phys.org/news/2026-02-mars-gps-perseverance-centimeters.html
1•PaulHoule•13m ago•1 comments

I turned down a $1M acquisition offer because I wanted to own what I built

https://useviralize.com
1•jcrosbz•14m ago•1 comments

Wolfenstein: Enemy Territory in emscripten, WS relay for online browser matches

https://et.klaussilveira.com
3•klaussilveira•15m ago•0 comments

Airbnb has a recruiting easter egg in its JavaScript output

https://www.airbnb.de/
1•datawars•15m ago•0 comments

OpenAI Fires an Employee for Prediction Market Insider Trading

https://www.wired.com/story/openai-fires-employee-insider-trading-polymarket-kalshi/
1•nadis•16m ago•0 comments

The LLM Sycophancy Antidote

https://photostructure.com/coding/sycophancy-antidote/
1•mceachen•17m ago•0 comments

Lessons from Building Claude Code: Seeing Like an Agent

https://twitter.com/trq212/status/2027463795355095314
1•nadis•18m ago•0 comments

Hyperion author Dan Simmons dies from stroke at 77

https://arstechnica.com/culture/2026/02/hyperion-author-dan-simmons-dies-from-stroke-at-77/
1•speckx•19m ago•0 comments

PicoClaw: Ultra-Efficient AI Assistant in Go

https://github.com/sipeed/picoclaw
1•xtracto•20m ago•0 comments

Show HN: Forgiven – A Vim/Spacemacs terminal editor with native Copilot agent

https://github.com/danebalia/forgiven
2•danebalia•21m ago•3 comments

Show HN: Goodfriendsbook.com Let's ask you, want opensourced to GitHub

1•gitprolinux•21m ago•1 comments

Lazard LCOE+ 2025 [pdf]

https://www.lazard.com/media/eijnqja3/lazards-lcoeplus-june-2025.pdf
1•toomuchtodo•22m ago•1 comments

Trump officials move to kill system that protects US from chemical disasters

https://www.theguardian.com/environment/2026/feb/27/trump-fire-chemical-safety-system-epa
5•mitchbob•23m ago•1 comments

NASA announces Artemis III mission no longer aims to send humans to moon

https://www.theguardian.com/science/2026/feb/27/nasa-changes-delays-moon-missions
3•bookofjoe•23m ago•3 comments

Why is getting a cheap prepaid SIM card in the USA so complicated?

1•huntsmans•26m ago•3 comments

Pure LLMs Score 0% on ARC-AGI-2. Why the Third Wave of AI Looks Like the First

https://ai.gopubby.com/neuro-symbolic-ai-arc-agi-alphaproof-third-wave-48177339d698
1•Aedelon•26m ago•0 comments

ByteDance Seed 2.0

https://seed.bytedance.com/en/blog/seed2-0-%E6%AD%A3%E5%BC%8F%E5%8F%91%E5%B8%83
1•kristianp•27m ago•0 comments

Our new frontier model: Ian

https://ian.ianmyjer.com/
2•enmyj•27m ago•0 comments

Warner Bros signs $110B deal with Paramount

https://www.reuters.com/sustainability/sustainable-finance-reporting/warner-bros-signs-110-billio...
4•Vitamin_Sushi•28m ago•2 comments

The Distillation Problem, It's Not a Cold War, It's Napster

https://www.stickybit.com.br/distillation-napster-en/
1•TiMagazine•28m ago•0 comments

Is This Waymo a Better Person Than You?

https://www.newyorker.com/humor/shouts-murmurs/is-this-waymo-a-better-person-than-you
1•mitchbob•29m ago•1 comments

Lasse Collin

https://liberapay.com/Larhzu/
1•pinkmuffinere•29m ago•0 comments

Ask HN: Apple locked me out of the developer program for a technical error

2•LoganDark•29m ago•0 comments

IronCurtain: A Personal AI Assistant Built Secure from the Ground Up

https://www.provos.org/p/ironcurtain-secure-personal-assistant/
1•jmort•30m ago•0 comments

Instant DB clones for AI agents

https://contextbits.com/
1•classx•32m ago•1 comments