frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Are Your Passwords in the Green? (2025)

https://www.hivesystems.com/blog/are-your-passwords-in-the-green
1•kemotep•9mo ago

Comments

kemotep•9mo ago
With NIST finally updating their standards to recommend 15 character password minimums last, I like to use their recommendations and compare them to these charts show how effective such a password would be.

Using E = L x log2(R), where E is entropy, L is number of characters in the password (15), and R is the total number of possible characters used (26 for all lowercase letters), you can get ~70 bits of entropy. Using a password manager like Bitwarden for a 15 character password using the full character set minus the ambiguous characters (65 characters total) leads to ~90 bits of entropy.

Using these charts and figures from the article, a well configured bcrypt setup means even the fastest computer systems still in 2025 cap out at 1 billion hashes per second for offline cracking (without getting into Nation States spending billions on just cracking your passwords, or dedicating all the world’s supercomputers or some other speculations). So to calculate how long it would take with a “realistic” password cracker in 2025, would use this formula:

((((((2^(70-1))/ 1 billion hashes per second)/ 60 seconds)/ 60 minutes)/ 24 hours)/ 365 days) to get ~18,700 years. (Nearly 20 billion years for the Bitwarden generated one)

But without a password filter checking for known bad passwords somewhere like Have I Been Pwned, even a 30 character password that has been leaked is useless. Would be instantly “cracked”. So I personally would have the password policy be:

1. 15 character minimum, no composition rules.

2. All passwords filtered for known bad passwords against HIBP.

3. Accounts protected by MFA.

4. Combination of network controls, best practices security configurations, and alerts and monitoring to help detect and limit/eliminate password guessing attacks, password database dumps.

FTSE 100 Live: Trillion-dollar tech sell-off rocks global markets

https://www.cityam.com/ftse-100-live-tech-sell-off-ai-trillion-bank-of-england-interest-rate-cut-...
1•user20180120•3m ago•0 comments

Show HN: Pit – Git for LLM prompts (332 tests, 10 features)

https://github.com/itisrmk/pit
1•rahulrmk•3m ago•0 comments

Codex is now over 1M active users

https://twitter.com/sama/status/2019219967250669741
1•tosh•4m ago•0 comments

Technology and Wealth: The Straw, the Siphon, and the Sieve

https://natehagens.substack.com/p/technology-and-wealth-the-straw-the-63d
1•thinkingemote•9m ago•0 comments

Ukraine starts blocking unregistered Starlink terminals

https://militarnyi.com/en/news/ukraine-starts-blocking-starlink-terminals/
1•defly•9m ago•0 comments

What are "shadow people" in the MWI

https://metallicman.com/laoban4site/what-are-shadow-people-in-the-mwi/
1•dsego•11m ago•0 comments

Commission Designates WhatsApp as Large Online Platform Under the DSA

https://digital-strategy.ec.europa.eu/en/news/commission-designates-whatsapp-very-large-online-pl...
2•riffraff•13m ago•0 comments

Show HN: vibesafu – YOLO mode for Claude Code, no –dangerously-skip-permission

https://github.com/kevin-hs-sohn/vibesafu
1•kevin-hs-sohn•17m ago•0 comments

Tailscale: Custom OIDC Providers

https://tailscale.com/docs/integrations/identity/custom-oidc
1•tosh•17m ago•0 comments

AI is taking devs' jobs. Yes, **BUT

1•olivdums•20m ago•1 comments

Hope Hacker conference is now a 501(c)(3) nonprofit

https://hope.net/
1•aestetix•20m ago•0 comments

CodeShield AI – Open-source security scanner (24% cheaper than GitGuardian)

https://lydiamorgan85.github.io/codeshield-ai/
1•CodeshieldAI•21m ago•1 comments

Battle-Testing Lynx at Allegro

https://blog.allegro.tech/2026/02/battle-testing-lynx-js-at-allegro.html
2•tgebarowski•22m ago•1 comments

What's the Entropy of a Random Integer?

https://quomodocumque.wordpress.com/2026/02/03/whats-the-entropy-of-a-random-integer/
1•sebg•23m ago•0 comments

How Democracy for Sale is making investigative journalism pay on Substack

https://pressgazette.co.uk/newsletters/peter-geoghegan-democracy-for-sale-investigative-journalis...
1•giuliomagnifico•26m ago•0 comments

U.S. House Report: E.U. Campaign to Censor the Internet [pdf]

https://judiciary.house.gov/sites/evo-subsites/republicans-judiciary.house.gov/files/2026-02/THE-...
2•stakhanov•27m ago•0 comments

Latrinalia

https://en.wikipedia.org/wiki/Latrinalia
1•chaghalibaghali•28m ago•0 comments

Libfirm/cparser: C99 parser and front end

https://github.com/libfirm/cparser
1•fanf2•29m ago•0 comments

Checking the Weather with a Home Made Satellite Dish (1973) [video]

https://www.youtube.com/watch?v=0EYntanZS1M
1•austinallegro•30m ago•0 comments

Why Do Monads Matter?

https://cdsmith.wordpress.com/2012/04/18/why-do-monads-matter/
1•sebg•32m ago•0 comments

Nanobot: Ultra-Lightweight Alternative to OpenClaw

https://github.com/HKUDS/nanobot
2•ms7892•32m ago•0 comments

26x

https://www.technicalchops.com/articles/26x/
1•mintone•32m ago•0 comments

Data breach: DOGE 'accidentally' leaked the whole Social Security database [pdf]

https://storage.courtlistener.com/recap/gov.uscourts.mdd.577321/gov.uscourts.mdd.577321.197.0.pdf
4•chirau•32m ago•0 comments

Show HN: Chronos – Historical timeline visualization tool that handles BCE dates

https://www.chronostimeline.com/
1•malvika109•34m ago•0 comments

Supreme Court lets California use its new congressional map

https://www.npr.org/2026/02/04/nx-s1-5691890/supreme-court-california-redistricting-map
2•rbanffy•39m ago•0 comments

What we've been getting wrong about AI's truth crisis

https://www.technologyreview.com/2026/02/02/1132068/what-weve-been-getting-wrong-about-ais-truth-...
1•rbanffy•39m ago•0 comments

PeerRank: Autonomous LLM Eval Through Web-Grounded,Bias-Controlled Peer Review

https://arxiv.org/abs/2602.02589
3•gaptaclod•40m ago•0 comments

Relative Age Effect

https://en.wikipedia.org/wiki/Relative_age_effect
1•wjb3•40m ago•0 comments

The Courage to Criticise

https://anupam.de/writing/essays/courageToCriticise.html
1•honey-badger•41m ago•0 comments

AWS intruder pulled off AI-assisted cloud break-in in 8 mins

https://www.theregister.com/2026/02/04/aws_cloud_breakin_ai_assist/
1•beardyw•42m ago•0 comments