# Threat Model for Login — Authentication & Authorization

Source: https://www.skillbyai.com/en/authentication/f-threats

> How attackers actually get in.

## The usual suspects

**Credential stuffing** replays username/password pairs leaked from other sites, exploiting password reuse; it is automated and distributed across many IPs. **Password spraying** tries a few common passwords against many accounts to dodge lockouts. **Phishing** tricks users into typing credentials (and even one-time codes) into a look-alike site, often relayed in real time. **Session hijacking** steals a session cookie or token (through XSS, malware or an insecure network) so the attacker never needs the password. **Account enumeration** uses differing error messages or timings to learn which emails are registered. Defences layer up: breached-password checks, rate limiting, MFA, phishing-resistant passkeys, hardened cookies and uniform responses.

## Threats and primary defences

A quick reference.

```text
threat                 primary defences
------                 ----------------
credential stuffing    MFA, breached-password checks, bot detection, rate limits
password spraying      rate limits per account AND per source, MFA, monitoring
phishing               passkeys / WebAuthn (origin-bound), user education
session hijacking      HttpOnly+Secure cookies, XSS prevention, short sessions
account enumeration    generic errors, same response for known/unknown users
brute force            slow hashing, throttling, progressive delays
```

## Assume passwords are already leaked

Design as if attackers hold a large list of real credentials. Controls that only work when passwords are secret are not enough on their own.

**Quiz:** Which factor resists real-time phishing best?

- [ ] A longer password
- [ ] An SMS one-time code
- [ ] A TOTP code from an app
- [x] A passkey (WebAuthn credential) bound to the site origin

*Answer:* A passkey (WebAuthn credential) bound to the site origin. WebAuthn signatures are bound to the origin, so a look-alike domain cannot use them.
