Sign-in and sessions.
WHAT TO USE
Established libraries, not your own implementation.
WHAT TO DO WITH PASSWORDS
Hash with an algorithm designed for passwords, which is deliberately slow.
WHAT NEVER TO DO
Store them recoverably Use general-purpose hashing Limit length or restrict characters Log them, in any form
WHAT TO CONFIGURE ON SESSION COOKIES
Secure transmission only Inaccessible to scripts Restricted cross-site sending A sensible expiry
WHAT TO DO ON SIGN-IN
Regenerate the session identifier.
WHAT TO DO ON SIGN-OUT
Destroy the session entirely.
WHAT TO DO ON PASSWORD CHANGE
Invalidate other sessions.
WHAT TO IMPLEMENT
Rate limiting on attempts Progressive delay or lockout A second authentication factor, where warranted
WHAT TO REVEAL ON FAILURE
Nothing about which part was wrong.
WHY
It otherwise confirms which accounts exist.
WHAT TO DO ON PASSWORD RESET
Issue a single-use token with a short expiry, invalidated once used.