Repository navigation
Conversation
The gate required 24+ characters AND upper, lower, digit and symbol. That rejects a 7-word Diceware passphrase (~90 bits) while passing "Aaaaaaaaaaaaaaaaaaaaaa1!". NIST SP 800-63B recommends length over composition rules. The existing rule is unchanged (and still what Generate produces). A second way to pass is added: 24+ characters made of 6+ different words of 3+ letters, separated by spaces, hyphens or underscores. Repeated words and single-letter 'words' do not count. Hint text, the rejection message and the README are updated to match. site/index.html and SHA256SUMS.txt are the rebuilt artifacts.
This was referenced Oct 6, 2026
Contributor
Author
|
Also available merged with every other review PR, in dependency order and verified together, as #57 — merge that or the individual PRs, not both. |
Owner
|
Thank you, Dean. I like the idea of accepting real passphrases, but this rule would also accept an ordinary sentence of common words, which is much weaker than its length suggests. That's a no-go for me, so I'm keeping the current password rule, and keeping the file as small and tight as possible. Please keep the suggestions coming! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
isPasswordStrongrequires 24+ characters and upper + lower + digit + symbol. That rejects a 7-word Diceware passphrase (correct horse battery staple whale pencil gravy, ~90 bits from the EFF long list) while acceptingAaaaaaaaaaaaaaaaaaaaaa1!. Composition rules optimise for the wrong thing — NIST SP 800-63B explicitly recommends length over composition — and passphrases are what people can actually remember for a 25-year secret.Change
The existing rule is unchanged (and still what Generate produces). A second way to pass the gate is added:
So
aaa aaa aaa aaa aaa aaa aaa aaa(repeated word) anda b c d e f g h i j k l(1-letter words) still fail;cat dog owl fox bee antfails on length.Updated to match: the field hint (
· 24+ chars with upper, lower, number, symbol — or a passphrase of 6+ words), the rejection message, and the README's strength-indicator bullet.Verified
app.jsand ran a 10-case table: all pass (Diceware with spaces/hyphens/underscores accepted; repeats, short words, 5 words, <24 chars,Tr0ub4dor&3rejected; the old composition rule behaves identically to before).site/index.html, typedcorrect horse battery staple whale pencil→ green border + "Password accepted" toast; CSP hashes re-pinned, no console errors.npm run test:crypto91/91 (no crypto touched — this is UI-layer only).site/index.htmlandSHA256SUMS.txtare the output ofnpm run build. Version string / CHANGELOG left to you.Note: touches the built
site/index.html, so it will conflict with #43 if both land — whichever merges second just needsnpm run buildre-run.