Skip to content

persistent-setup: estimate strength with zxcvbn - #309

Open
BenWestgate wants to merge 1 commit into
masterfrom
passphrase-strength-zxcvbn
Open

BenWestgate wants to merge 1 commit into
masterfrom
passphrase-strength-zxcvbn

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Tails 7.6 (March 2026) replaced KeePassXC with the Secrets password manager, so keepassxc-cli no longer exists. persistent-setup called keepassxc-cli estimate. On Tails 7.6 and later that returns nothing, the empty value counts as 0 bits, and every existing passphrase gets the "WARNING: Weak Passphrase Detected" dialog, however strong it is.

Change

  • A small passphrase_bits helper now estimates strength with zxcvbn, the same estimator KeePassXC used.
    • On Tails 7.14, keepassxc-cli and the Python zxcvbn module are both missing, but Secrets is installed. Recent Secrets uses the Rust port, zxcvbn_rs_py, so the helper tries that first and falls back to the Python zxcvbn.
    • The Rust port counts guesses in a 64-bit integer, so it never reports more than 64 bits. The pass mark moves from 65 to 64 bits; otherwise no passphrase could pass. 5 random words, as Tails recommends, reach the cap and pass.
  • The passphrase is passed on stdin, not as a command-line argument, so it never shows up in a process list. keepassxc-cli estimate took it as an argument.
  • If no estimator is installed, the user sees "Passphrase strength not checked" instead of being told the passphrase is weak. This follows the draft maintainability policy (docs: define maintainability and PELD policy #277): keep dependency failures visible, don't silently swallow them.

Testing

  • Rust port (zxcvbn-rs-py 0.3.0) and Python zxcvbn give the same scores up to the cap:
    • "correcthorsebatterystaple": 47 bits in both
    • "Tr0ub4dor&3": 36 bits in both
    • 4 random words: 55 bits (Rust); 5 or 6 random words: 64 bits (Rust, capped), 67–83 bits (Python)
  • With neither module installed, the helper exits non-zero, which takes the "not checked" path.
  • shellcheck with CI's flags passes.
  • Still needs a run on Tails 7.14 to confirm zxcvbn_rs_py is importable there.

#293 also edits this file. Whichever merges second will have a small conflict on these lines.

Refs #243

🤖 Generated with Claude Code

https://claude.ai/code/session_01LvEHMDeHvYQYDEkpJn95X8

@chatgpt-codex-connector

This comment has been minimized.

Copy link
Copy Markdown
Owner Author

github-advanced-security fails here because of a repository setting, not this change. It fails the same way on every open PR and the run reports no findings. Nothing in this PR can fix it, so I'm ignoring it as instructed.


Generated by Claude Code

@BenWestgate
BenWestgate force-pushed the passphrase-strength-zxcvbn branch from aeab51a to bec02d2 Compare October 2, 2026 18:50
Tails 7.6 replaced KeePassXC with Secrets, so keepassxc-cli no longer
exists. The empty estimate counted as zero bits, and every existing
passphrase was reported as too weak, however strong.

Estimate with zxcvbn instead, the same estimator KeePassXC used. Tails
7.14 ships its Rust port, zxcvbn_rs_py, as a dependency of Secrets;
fall back to the Python zxcvbn where that is what is installed. The
Rust port counts guesses in 64 bits, so it reports at most 64 bits of
strength. Pass at 64 bits instead of 65, so that a passphrase of 5 or
more random words, as Tails recommends, still passes.

Pass the passphrase on stdin so it never appears in a process list.
If no estimator is installed, say the strength was not checked
instead of calling the passphrase weak.

Refs #243
@BenWestgate
BenWestgate force-pushed the passphrase-strength-zxcvbn branch from bec02d2 to 127895d Compare October 3, 2026 07:39

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex current-head review at 127895d: no findings. The passphrase stays off argv, both Tails-era zxcvbn APIs are handled, numeric output is validated before arithmetic, and an unavailable estimator is surfaced explicitly rather than misclassified as a strength result.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted current-head security verification: ACK 127895d for the audited passphrase-argv exposure. The old keepassxc-cli estimate <passphrase> process argument is removed. persistent-setup strips spaces in the parent shell and sends the resulting passphrase only on stdin to a fixed python3 -c program; neither argv nor environment contains it. The helper imports only the local zxcvbn estimator and returns a numeric estimate; unavailable/broken estimators take an explicit warning path rather than reintroducing another secret channel. Exact-head Lint CI, Dependency Review, and CodeQL are green and there are no unresolved review threads. Supported-Tails confirmation that zxcvbn_rs_py is actually installed/importable is still a runtime qualification item, but absence fails to the visible 'strength not checked' path and does not reopen the argv disclosure.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants