{"query": "The strength of a password, in bits", "count": 20, "results": [{"id": "card_works_password", "title": "The strength of a password, in bits", "shelf": "the-works", "surface": "secular", "snippet": "A 12-character password from a 95-symbol keyboard carries about 79 bits of entropy — H = L·log₂(N); and a CVSS score of 9.1 is, by the standard, a critical vulnerability.  Worked & sealed by the engin", "authority_tier": "verified", "source": "The Works — worked & sealed", "generated": false}, {"id": "card_theory_cryptographic_security", "title": "Cryptographic security (hashing, checksums, PKI)", "shelf": "theories", "surface": "secular", "snippet": "Cryptographic security (hashing, checksums, PKI) — an engine domain that can touch it: cybersecurity. Calibration: seals — digests and signatures verify exactly. Three different things people routinel", "authority_tier": "reference", "source": "The Theory Assay — calibrated, not judged (docs/THEORY_CATALOG.md)", "generated": false}, {"id": "card_domchk_cybersecurity_claimed_entropy_bits", "title": "Cybersecurity: entropy bits", "shelf": "cybersecurity", "surface": "secular", "snippet": "A worked check in cybersecurity: entropy bits.\n\nGIVEN\n  charset_size = 94\n  cidr_prefix = 24\n  cvss_base_score = 9.1\n  password_length = 16\n  port_number = 443\n  tls_version = 1.2\n\nCLAIMED\n  claimed_e", "authority_tier": "reference", "source": "The verifier's own documented relation, and a run this engine performed against it (deterministic; re-runnable with tools/domain_goldens.py)", "generated": false}, {"id": "card_src_rfc_3244", "title": "RFC3244 — Microsoft Windows 2000 Kerberos Change Password and Set Password Protocols", "shelf": "rfcs", "surface": "secular", "snippet": "RFC3244: Microsoft Windows 2000 Kerberos Change Password and Set Password Protocols (February 2002). Status: INFORMATIONAL.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_v_dcca79ff2b8e", "title": "H = 12·log₂(95) ≈ 78.84 bits · CVSS 9.1 → critical", "shelf": "cybersecurity", "surface": "secular", "snippet": "Verdict: HOLDS.\n• cybersecurity.password_entropy: H = 78.84 bits (matches claim)\n• cybersecurity.cvss_severity: CVSS 9.1 → 'critical' (matches claim)\nSealed and independently re-checkable: https://nar", "authority_tier": "engine", "source": "Verified by the engine — cybersecurity", "generated": false}, {"id": "card_src_rfc_4013", "title": "RFC4013 — SASLprep: Stringprep Profile for User Names and Passwords", "shelf": "rfcs", "surface": "secular", "snippet": "RFC4013: SASLprep: Stringprep Profile for User Names and Passwords (March 2005). Status: PROPOSED STANDARD. Obsoleted by RFC7613.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_8265", "title": "RFC8265 — Preparation, Enforcement, and Comparison of Internationalized Strings Representing Usernames and Passwords", "shelf": "rfcs", "surface": "secular", "snippet": "RFC8265: Preparation, Enforcement, and Comparison of Internationalized Strings Representing Usernames and Passwords (October 2017). Status: PROPOSED STANDARD. Obsoletes RFC7613.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_7613", "title": "RFC7613 — Preparation, Enforcement, and Comparison of Internationalized Strings Representing Usernames and Passwords", "shelf": "rfcs", "surface": "secular", "snippet": "RFC7613: Preparation, Enforcement, and Comparison of Internationalized Strings Representing Usernames and Passwords (August 2015). Status: PROPOSED STANDARD. Obsoleted by RFC8265. Obsoletes RFC4013.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_port_tcp_586_password_chg", "title": "Port 586/tcp — password-chg", "shelf": "networking", "surface": "secular", "snippet": "Port 586/tcp is assigned to password-chg: Password Change.", "authority_tier": "reference", "source": "IANA Service Name and Port Number Registry (public domain)", "generated": false}, {"id": "card_src_port_udp_586_password_chg", "title": "Port 586/udp — password-chg", "shelf": "networking", "surface": "secular", "snippet": "Port 586/udp is assigned to password-chg: Password Change.", "authority_tier": "reference", "source": "IANA Service Name and Port Number Registry (public domain)", "generated": false}, {"id": "card_src_rfc_4746", "title": "RFC4746 — Extensible Authentication Protocol (EAP) Password Authenticated Exchange", "shelf": "rfcs", "surface": "secular", "snippet": "RFC4746: Extensible Authentication Protocol (EAP) Password Authenticated Exchange (November 2006). Status: INFORMATIONAL.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_8018", "title": "RFC8018 — PKCS #5: Password-Based Cryptography Specification Version 2.1", "shelf": "rfcs", "surface": "secular", "snippet": "RFC8018: PKCS #5: Password-Based Cryptography Specification Version 2.1 (January 2017). Status: INFORMATIONAL. Obsoletes RFC2898.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_2898", "title": "RFC2898 — PKCS #5: Password-Based Cryptography Specification Version 2.0", "shelf": "rfcs", "surface": "secular", "snippet": "RFC2898: PKCS #5: Password-Based Cryptography Specification Version 2.0 (September 2000). Status: INFORMATIONAL. Obsoleted by RFC8018.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_5931", "title": "RFC5931 — Extensible Authentication Protocol (EAP) Authentication Using Only a Password", "shelf": "rfcs", "surface": "secular", "snippet": "RFC5931: Extensible Authentication Protocol (EAP) Authentication Using Only a Password (August 2010). Status: INFORMATIONAL.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_9383", "title": "RFC9383 — SPAKE2+, an Augmented Password-Authenticated Key Exchange (PAKE) Protocol", "shelf": "rfcs", "surface": "secular", "snippet": "RFC9383: SPAKE2+, an Augmented Password-Authenticated Key Exchange (PAKE) Protocol (September 2023). Status: INFORMATIONAL.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_7894", "title": "RFC7894 — Alternative Challenge Password Attributes for Enrollment over Secure Transport", "shelf": "rfcs", "surface": "secular", "snippet": "RFC7894: Alternative Challenge Password Attributes for Enrollment over Secure Transport (June 2016). Status: PROPOSED STANDARD.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_8133", "title": "RFC8133 — The Security Evaluated Standardized Password-Authenticated Key Exchange (SESPAKE) Protocol", "shelf": "rfcs", "surface": "secular", "snippet": "RFC8133: The Security Evaluated Standardized Password-Authenticated Key Exchange (SESPAKE) Protocol (March 2017). Status: INFORMATIONAL.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_9588", "title": "RFC9588 — Kerberos Simple Password-Authenticated Key Exchange (SPAKE) Pre-authentication", "shelf": "rfcs", "surface": "secular", "snippet": "RFC9588: Kerberos Simple Password-Authenticated Key Exchange (SPAKE) Pre-authentication (August 2024). Status: PROPOSED STANDARD.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_6631", "title": "RFC6631 — Password Authenticated Connection Establishment with the Internet Key Exchange Protocol version 2 (IKEv2)", "shelf": "rfcs", "surface": "secular", "snippet": "RFC6631: Password Authenticated Connection Establishment with the Internet Key Exchange Protocol version 2 (IKEv2) (June 2012). Status: EXPERIMENTAL.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}, {"id": "card_src_rfc_9106", "title": "RFC9106 — Argon2 Memory-Hard Function for Password Hashing and Proof-of-Work Applications", "shelf": "rfcs", "surface": "secular", "snippet": "RFC9106: Argon2 Memory-Hard Function for Password Hashing and Proof-of-Work Applications (September 2021). Status: INFORMATIONAL.", "authority_tier": "reference", "source": "The RFC Index (RFC Editor / IETF) — public domain", "generated": false}]}