frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•1y ago

Comments

kemotep•1y ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

After 80 Years, Mathematicians Give Famed 'Erdős Method' an Upgrade

https://www.quantamagazine.org/after-80-years-mathematicians-give-famed-erdos-method-an-upgrade-2...
1•signa11•1m ago•0 comments

Grantham Warns U.S. Stocks Could Plunge 70% / Most Expensive Market in History

https://247wallst.com/investing/2026/06/26/jeremy-grantham-warns-u-s-stocks-could-plunge-70-in-th...
1•andsoitis•7m ago•0 comments

Feds Killed Polestar and Spared Volvo. That Should Terrify You

https://www.thedrive.com/news/feds-killed-polestar-and-spared-volvo-that-should-terrify-you
2•mraniki•13m ago•3 comments

I built a 100% local network privacy appliance to stop smart home spying

https://www.edgedefenseai.com/
1•arundass•15m ago•1 comments

China Has Matched Anthropic in Cybersecurity, Resetting AI Race

https://www.wsj.com/tech/ai/chinese-ai-anthropic-mythos-cybersecurity-574b02c2
1•madars•16m ago•2 comments

What Happens When You Run 10k Concurrent Lambda Functions Against DynamoDB

https://medium.com/@yalovoy/what-happens-when-you-run-10-000-concurrent-lambda-functions-against-...
1•zero-ground-445•17m ago•0 comments

Amble One

https://driveamble.com/pages/amble-one
2•dnw•20m ago•0 comments

Show HN: FSM – an advanced system monitor for Linux

https://github.com/mskrasnov/FSM
1•mskrasnov•22m ago•0 comments

The AI "Super Bubble" Warning Is a Filter, Not a Funeral

https://www.pentesty.co/blog/ai-super-bubble-cybersecurity-filter-2026
2•johnzoro107•25m ago•0 comments

Show HN: SpinnerRecruit – targeted job ads in CLI for AI wait states

https://www.spinnerrecruit.dev/
1•jamessmu•27m ago•2 comments

Response to AI slop is from Robin Williams

https://jayacunzo.com/blog/your-move-chief
8•herbertl•40m ago•0 comments

Chrome Extension to Bypass Paywalls

https://gitflic.ru/project/magnolia1234/bypass-paywalls-chrome-clean
1•thunderbong•40m ago•1 comments

Turning music into a chore is how I became a musician

https://the.scapegoat.dev/turning-music-into-a-chore-is-what-made-me-an-artist/
2•herbertl•46m ago•0 comments

Microchip June 2026: AVR LA Family [pdf]

https://ww1.microchip.com/downloads/aemDocuments/documents/MCU08/ProductDocuments/Brochures/AVR-L...
2•dragontamer•47m ago•1 comments

Show HN: Decomp Academy – Learn to decompile GameCube games into matching C

https://decomp-academy.dev
18•jackpriceburns•47m ago•6 comments

Show HN: Shopify UCP is insanely powerful

https://stack412.com/
2•westche2222•55m ago•2 comments

I designed and synthesized PAC-832 in a chemistry lab I built in my garage

https://twitter.com/DouglasYaoDY/status/2070904914050797582
3•gasull•58m ago•1 comments

People and Blogs Interview: David Cain, Raptitude

https://manuelmoreale.com/interview/david-cain
3•Curiositry•59m ago•0 comments

From Prompting Agents to Loop Engineering

https://twitter.com/omarsar0/status/2068008743153832264
5•gmays•1h ago•1 comments

Slop, trust, and a three-line patch

https://klez.me/2026/06/28/slop-trust-and-a-three-line-patch/
2•the_kLeZ•1h ago•1 comments

Google Patent Reveals Satellite Messages May Carry Device Tracking Data

https://patentlyze.com/patent/google-stuffing-device-data-satellite-messages/
3•Dfol•1h ago•2 comments

Show HN: Moumantai – self-hosted, agent-driven apps you can use on any device

https://github.com/xiang-deng/moumantai
2•no_0044•1h ago•0 comments

AMD Strix Halo RDMA Cluster Setup Guide

https://github.com/kyuz0/amd-strix-halo-vllm-toolboxes/blob/main/rdma_cluster/setup_guide.md
21•jakogut•1h ago•0 comments

GTA 3 on a Volumetric Display (2025) [video]

https://www.youtube.com/watch?v=onYH5gvlnzE
2•Tiberium•1h ago•0 comments

Australia to double maximum penalty for platforms in breach of social media ban

https://www.bbc.co.uk/news/articles/c78yv5g74e9o
2•bbg2401•1h ago•1 comments

Never before have so many been trapped in place

https://kindofvoiceless.substack.com/p/there-will-be-nowhere-to-go
4•OgsyedIE•1h ago•0 comments

Why American data centers can't plug in

https://worksinprogress.co/issue/why-american-data-centers-cant-plug-in/
5•Gaishan•1h ago•0 comments

The Lost Discipline of the Alarm: What Notification Design Forgot [video]

https://www.youtube.com/watch?v=Ira28fgSF7M
3•jumpocelot•1h ago•0 comments

Nix Taco Sprint 2026

https://jrdsgl.com/nix-taco-sprint-2026/
6•alurm•1h ago•0 comments

Show HN: QR code renderer in a TrueType font

https://qr.jim.sh/
2•foodevl•1h ago•1 comments