mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-06 03:38:23 +00:00
NIP-49 sets no minimum, but an ncryptsec can be brute-forced offline with no rate limit at one scrypt(2^16) per guess. The Android backup screen, the desktop backup card and desktop onboarding now require at least 12 characters before encrypting. A hint under the password field turns primary once it is met. The rule lives in quartz (Nip49.MIN_PASSWORD_LENGTH / isLongEnough). It counts code points of the NFKC-normalized password, i.e. what scrypt actually sees, so an emoji counts once. It applies only at creation: decrypting and login still accept any password, so ncryptsecs made elsewhere keep opening. The CLI is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012hhtLQhig6Wmt5U4C3owaP