Repository navigation
persistent-setup: estimate strength with zxcvbn - #309
BenWestgate wants to merge 1 commit into
Conversation
This comment has been minimized.
This comment has been minimized.
|
Generated by Claude Code |
aeab51a to
bec02d2
Compare
Tails 7.6 replaced KeePassXC with Secrets, so keepassxc-cli no longer exists. The empty estimate counted as zero bits, and every existing passphrase was reported as too weak, however strong. Estimate with zxcvbn instead, the same estimator KeePassXC used. Tails 7.14 ships its Rust port, zxcvbn_rs_py, as a dependency of Secrets; fall back to the Python zxcvbn where that is what is installed. The Rust port counts guesses in 64 bits, so it reports at most 64 bits of strength. Pass at 64 bits instead of 65, so that a passphrase of 5 or more random words, as Tails recommends, still passes. Pass the passphrase on stdin so it never appears in a process list. If no estimator is installed, say the strength was not checked instead of calling the passphrase weak. Refs #243
bec02d2 to
127895d
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head review at 127895d: no findings. The passphrase stays off argv, both Tails-era zxcvbn APIs are handled, numeric output is validated before arithmetic, and an unavailable estimator is surfaced explicitly rather than misclassified as a strength result.
BenWestgate
left a comment
There was a problem hiding this comment.
AI-assisted current-head security verification: ACK 127895d for the audited passphrase-argv exposure. The old keepassxc-cli estimate <passphrase> process argument is removed. persistent-setup strips spaces in the parent shell and sends the resulting passphrase only on stdin to a fixed python3 -c program; neither argv nor environment contains it. The helper imports only the local zxcvbn estimator and returns a numeric estimate; unavailable/broken estimators take an explicit warning path rather than reintroducing another secret channel. Exact-head Lint CI, Dependency Review, and CodeQL are green and there are no unresolved review threads. Supported-Tails confirmation that zxcvbn_rs_py is actually installed/importable is still a runtime qualification item, but absence fails to the visible 'strength not checked' path and does not reopen the argv disclosure.
Tails 7.6 (March 2026) replaced KeePassXC with the Secrets password manager, so
keepassxc-clino longer exists.persistent-setupcalledkeepassxc-cli estimate. On Tails 7.6 and later that returns nothing, the empty value counts as 0 bits, and every existing passphrase gets the "WARNING: Weak Passphrase Detected" dialog, however strong it is.Change
passphrase_bitshelper now estimates strength with zxcvbn, the same estimator KeePassXC used.keepassxc-cliand the Pythonzxcvbnmodule are both missing, but Secrets is installed. Recent Secrets uses the Rust port,zxcvbn_rs_py, so the helper tries that first and falls back to the Pythonzxcvbn.keepassxc-cli estimatetook it as an argument.Testing
zxcvbn_rs_pyis importable there.#293 also edits this file. Whichever merges second will have a small conflict on these lines.
Refs #243
🤖 Generated with Claude Code
https://claude.ai/code/session_01LvEHMDeHvYQYDEkpJn95X8