Files
amethyst/commonsUI
Claude b3aebaa95b feat: require 12+ character passwords when creating an ncryptsec
NIP-49 sets no minimum, but an ncryptsec can be brute-forced offline with no
rate limit at one scrypt(2^16) per guess. The Android backup screen, the desktop
backup card and desktop onboarding now require at least 12 characters before
encrypting. A hint under the password field turns primary once it is met.

The rule lives in quartz (Nip49.MIN_PASSWORD_LENGTH / isLongEnough). It counts
code points of the NFKC-normalized password, i.e. what scrypt actually sees,
so an emoji counts once. It applies only at creation: decrypting and login
still accept any password, so ncryptsecs made elsewhere keep opening. The CLI
is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012hhtLQhig6Wmt5U4C3owaP
2026-09-26 20:54:20 +00:00
..