← Back to catalogue
Research draft

password

vr.tr.password · XCT.QLT

Let an agent explain passwords and their role in authentication, relay security guidance from bodies such as NIST and national cyber security centres, describe attacks in general terms and defences, and decline to help obtain or crack passwords belonging to others.

Thing Registry Cross-cutting context

Research draft, second pass

A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.

written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify

Researched by: Claude

Purpose and description

Let an agent explain passwords and their role in authentication, relay security guidance from bodies such as NIST and national cyber security centres, describe attacks in general terms and defences, and decline to help obtain or crack passwords belonging to others.

A secret string of characters used to authenticate a user to a system, service or device, including numeric personal identification numbers, device PINs, one-time passwords generated for a single use, default passwords set by manufacturers, and transfer authorisation codes such as domain AuthInfo codes; passwords are the most common authentication factor, are protected by hashing and policy, are attacked by guessing, phishing and breaches, and are increasingly supplemented or replaced by multi-factor authentication and passkeys.

What it is for: Authenticating identity to systems.

It can be explain the concept and kinds; relay security guidance; describe threats and defences in general terms; route to password managers and MFA.

Distinguishing features

Shared secret

Knowledge factor

Strength depends on length and unpredictability

Vulnerable to reuse and phishing

What it looks like

Not a visible object; a secret string entered into a login field.

How it is recognised

Secret string for authentication

Passwords, PINs, one-time passwords, default passwords, AuthInfo codes

Usernames are public identifiers; biometrics and hardware keys are other factors; passkeys replace passwords

Related models

is a kind of - in registry terms

shared secret

is a kind of - in registry terms

personal data

is a kind of - in registry terms

string

is used in - as a knowledge factor

authentication

In practice

Families and kinds

user-chosen passwords and passphrases

personal identification numbers and device PINs

one-time passwords and time-based codes

default and initial passwords

authorisation codes such as domain AuthInfo

system-generated and manager-stored passwords

Standards and regulation

NIST SP 800-63B digital identity guidelines

National cyber security centre password guidance

Laws banning default passwords on consumer devices such as the UK PSTI Act

Data protection rules on credential storage

Failure modes and hazards

Weak and reused passwords

Phishing and credential breaches

Default passwords left unchanged

Agents assisting unauthorised access

Also called

personal identification numbersafe passwordone-time passworddevice PINdefault passwordAuthInfopassphrasetransaction authentication number

Where this came from

wikidata · CC0 1.0

Drafted structure

Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.

Understand What a password is.

Definition.

Definition

Definition and kinds.

Definition

Definition.

  1. What is a password, and what kinds of password-like secrets exist? definition
  2. Is the user seeking to access an account that is not theirs, which the model refuses, or general information? boundary

Strength

Strength and choice.

Strength

Strength.

  1. What makes a password strong, and what do current guidelines recommend? provenance
  2. Which entry fits password strength? action
Protect Protection and management.

Regulation.

Guidance

Guidance.

Guidance

Guidance.

  1. What do NIST and national bodies advise on password policy, storage and rotation? provenance
  2. Which references are standard? provenance

Tools

Managers and MFA.

Tools

Tools.

  1. How do password managers, multi-factor authentication and passkeys reduce risk? provenance
  2. Which entry fits password manager? action
Threats Threats.

Security.

Attacks

Attacks in general terms.

Attacks

Attacks.

  1. What kinds of attack target passwords, and how are they defended against, in general terms? provenance
  2. Is the presentation free of operational attack detail? boundary

Breaches

Breaches and response.

Breaches

Breaches.

  1. What should people do after a breach, and how do breach notification services work? action
  2. Which sources are cited? provenance
Context Systems and history.

Context.

Systems

Storage and hashing.

Systems

Systems.

  1. How do systems store passwords securely with hashing and salting? provenance
  2. Which entry fits password hashing? action

History

History and future.

History

History.

  1. How did computer passwords develop, and how are passkeys changing authentication? provenance
  2. Which entry fits passkey? action

What the second pass must settle

  • Should one-time password and passkey be separate entries?
  • How should security guidance be linked?
  • The registry entry has merged aliases naming specific credential types; should they be split off?