Knowledgebase

Securing Authentication in Web Applications Print

  • webdevelopment, security, password, domainrenewal, woocommerce, performance, guide, howto
  • 0

Sign-in and sessions.

WHAT TO USE

Established libraries, not your own implementation.

WHAT TO DO WITH PASSWORDS

Hash with an algorithm designed for passwords, which is deliberately slow.

WHAT NEVER TO DO

Store them recoverably Use general-purpose hashing Limit length or restrict characters Log them, in any form

WHAT TO CONFIGURE ON SESSION COOKIES

Secure transmission only Inaccessible to scripts Restricted cross-site sending A sensible expiry

WHAT TO DO ON SIGN-IN

Regenerate the session identifier.

WHAT TO DO ON SIGN-OUT

Destroy the session entirely.

WHAT TO DO ON PASSWORD CHANGE

Invalidate other sessions.

WHAT TO IMPLEMENT

Rate limiting on attempts Progressive delay or lockout A second authentication factor, where warranted

WHAT TO REVEAL ON FAILURE

Nothing about which part was wrong.

WHY

It otherwise confirms which accounts exist.

WHAT TO DO ON PASSWORD RESET

Issue a single-use token with a short expiry, invalidated once used.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot