password
Let an agent explain passwords and their role in authentication, relay security guidance from bodies such as NIST and national cyber security centres, describe attacks in general terms and defences, and decline to help obtain or crack passwords belonging to others.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify
Researched by: Claude
Purpose and description
Let an agent explain passwords and their role in authentication, relay security guidance from bodies such as NIST and national cyber security centres, describe attacks in general terms and defences, and decline to help obtain or crack passwords belonging to others.
A secret string of characters used to authenticate a user to a system, service or device, including numeric personal identification numbers, device PINs, one-time passwords generated for a single use, default passwords set by manufacturers, and transfer authorisation codes such as domain AuthInfo codes; passwords are the most common authentication factor, are protected by hashing and policy, are attacked by guessing, phishing and breaches, and are increasingly supplemented or replaced by multi-factor authentication and passkeys.
What it is for: Authenticating identity to systems.
It can be explain the concept and kinds; relay security guidance; describe threats and defences in general terms; route to password managers and MFA.
Distinguishing features
Shared secret
Knowledge factor
Strength depends on length and unpredictability
Vulnerable to reuse and phishing
What it looks like
Not a visible object; a secret string entered into a login field.
How it is recognised
Secret string for authentication
Passwords, PINs, one-time passwords, default passwords, AuthInfo codes
Usernames are public identifiers; biometrics and hardware keys are other factors; passkeys replace passwords
Related models
is a kind of - in registry terms
is a kind of - in registry terms
is a kind of - in registry terms
is used in - as a knowledge factor
In practice
Families and kinds
user-chosen passwords and passphrases
personal identification numbers and device PINs
one-time passwords and time-based codes
default and initial passwords
authorisation codes such as domain AuthInfo
system-generated and manager-stored passwords
Standards and regulation
NIST SP 800-63B digital identity guidelines
National cyber security centre password guidance
Laws banning default passwords on consumer devices such as the UK PSTI Act
Data protection rules on credential storage
Failure modes and hazards
Weak and reused passwords
Phishing and credential breaches
Default passwords left unchanged
Agents assisting unauthorised access
Also called
Where this came from
wikidata · CC0 1.0
Drafted structure
Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.
Understand What a password is.
Definition.
Definition
Definition and kinds.
Definition
Definition.
- What is a password, and what kinds of password-like secrets exist? definition
- Is the user seeking to access an account that is not theirs, which the model refuses, or general information? boundary
Strength
Strength and choice.
Strength
Strength.
- What makes a password strong, and what do current guidelines recommend? provenance
- Which entry fits password strength? action
Protect Protection and management.
Regulation.
Guidance
Guidance.
Guidance
Guidance.
- What do NIST and national bodies advise on password policy, storage and rotation? provenance
- Which references are standard? provenance
Tools
Managers and MFA.
Tools
Tools.
- How do password managers, multi-factor authentication and passkeys reduce risk? provenance
- Which entry fits password manager? action
Threats Threats.
Security.
Attacks
Attacks in general terms.
Attacks
Attacks.
- What kinds of attack target passwords, and how are they defended against, in general terms? provenance
- Is the presentation free of operational attack detail? boundary
Breaches
Breaches and response.
Breaches
Breaches.
- What should people do after a breach, and how do breach notification services work? action
- Which sources are cited? provenance
Context Systems and history.
Context.
Systems
Storage and hashing.
Systems
Systems.
- How do systems store passwords securely with hashing and salting? provenance
- Which entry fits password hashing? action
History
History and future.
History
History.
- How did computer passwords develop, and how are passkeys changing authentication? provenance
- Which entry fits passkey? action
What the second pass must settle
- Should one-time password and passkey be separate entries?
- How should security guidance be linked?
- The registry entry has merged aliases naming specific credential types; should they be split off?