(CASE STUDY · 09)
STRENGTHX
- Password Security
- Python
- Streamlit
- Have I Been Pwned
- Ollama
StrengthX is a password checker that asks two questions at once: how hard is this password to guess, and has it already leaked? The zxcvbn library answers the first and Have I Been Pwned the second. When either answer is bad, StrengthX AI can write a new password.
- ROLE
- Backend, AI & UI
- TIMELINE
- 8 Months
- YEAR
- 2025-2026
- TEAM
- 5 Contributors
(MY ROLE)
- Wrote 171 of the 176 commits and all 647 lines of today's main.py.
- Built the analyzer: zxcvbn scoring, a k-anonymity breach check against Have I Been Pwned, and a 5-rule checklist.
- Added StrengthX AI on a custom Ollama model, then dropped the Gemini fallback for a visible error.
- Packed it in Docker, set up the flake8 CI, and rebuilt the whole interface in June 2026.
- (WHY IT EXISTS)
- A strength meter says how hard a password is to guess. It says nothing about whether the password is already on a breach list. StrengthX puts both answers on one screen.
- (STRONG IS NOT THE SAME AS SAFE)
- “correct horse battery staple” scores 4 of 4 and would take centuries to crack offline. Checked in September 2026, Have I Been Pwned had seen it 391 times in breach data. “Tr0ub4dor&3” scores 4 of 4 too, and had been seen 3,196 times.
- (WHAT CHANGED)
- It began as a terminal loop around zxcvbn. The breach check came the next day, and the first Streamlit page 10 days in. In June 2026 the page was rebuilt around a 5-bar meter, 3 tiles and a pass-or-fail checklist.
Process
-
01
Terminal First
A 25-line Python loop: type a password, get a zxcvbn score from 0 to 4 with its warning and suggestions. The meter still shows that same scale.
-
02
Breach Check
The password is hashed with SHA-1 and only the first 5 characters go to Have I Been Pwned. The other 35 never leave: the app matches them against the list that comes back.
-
03
Web App & AI
Moved to a Streamlit page, then added an AI button that asks a custom Ollama model for a new password.
-
04
Docker & CI
Packed it in a Docker image that reads the host's port, and turned off error details so nobody sees a stack trace. A flake8 check, set up just before the AI, runs on pushes and pull requests to main.
How It Works
Every press of Enter reruns the whole Streamlit script, so both checks run and the verdict redraws in one pass. The AI generator sits apart and only runs on a click.
The Analyzer
The verdict reads top to bottom: a meter in the score's colour, a breach banner, then three tiles for Crack Time, Entropy and Breaches. A weak password goes red at once. A strong one can still fail the second question.
In The Detail
The checklist replaced four hints that only appeared on failure with five rules that always show pass or fail. The AI popover asks for a password of at least 16 characters, and says plainly when the model cannot be reached.
(SYSTEM · PRIVACY)
What Leaves The Server
The password travels from the browser to the app server over Streamlit's WebSocket, and every check runs there.
(SCOPE)
- hash characters sent to Have I Been Pwned
- 5 of 40
- outside services the server calls, one only on a click
- 2
- files, logs or databases the app writes to
- 0
WHAT STAYS, WHAT LEAVES
- Your password
- Sent to the app server and held in the session's memory.
- Its SHA-1 hash
- Computed on the server with hashlib, used only for the breach lookup.
- 5 hash characters
- The only part sent to api.pwnedpasswords.com, which answers with every suffix that shares them.
- The AI prompt
- Fixed text, the same for everyone. Your password is never in it.
One Scroll
Every answer sits on one scroll: the verdict, zxcvbn's warning and suggestion, the checklist, then a short guide to how the checks work. It is one Streamlit script, rendered top to bottom. On a phone its tiles and steps stack into one column. A floating AI button opens the generator in a popover at any width.
-
The verdict
-
Security intelligence
-
How the checks work
-
StrengthX AI