# Authentication Failures — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/u-auth

> Credential stuffing, weak recovery, missing MFA.

## Make account takeover hard

Common authentication failures: permitting weak or breached passwords, no protection against automated **credential stuffing** and brute force, user enumeration through different error messages, weak password recovery (guessable questions, long-lived reset links), and no **multi-factor authentication (MFA)**. Defences: offer phishing-resistant MFA (passkeys/WebAuthn) or at least TOTP, rate limit and detect suspicious logins, use generic error messages, make reset tokens single-use and short-lived, and prefer a proven identity provider over custom code.

## Know who users are, notice attacks

Robust authentication and sessions keep accounts safe; logging and monitoring detect attacks in progress.

![Three ideas: authentication, sessions and tokens, logging and monitoring.](assets/figures/owasp-top-10/section-7-map.svg) — Figure 7.1 — Authentication, sessions and monitoring.

## Login hardening checklist

Controls for a login and recovery flow.

```text
- generic message: "Invalid email or password" for both unknown user and wrong password
- rate limit per account and per IP; exponential backoff; alert on spikes
- breached-password check at sign-up and password change
- MFA available (passkeys preferred), required for admins
- reset tokens: random, single-use, expire in ~15-60 minutes, invalidated after password change
- notify users of new sign-ins and security changes
```

## Prefer passkeys

WebAuthn passkeys are bound to the site's origin, so they resist phishing far better than passwords plus SMS codes.

**Quiz:** What is credential stuffing?

- [ ] Filling a form automatically for accessibility
- [ ] Storing too many passwords
- [ ] Encrypting credentials twice
- [x] Trying username and password pairs leaked from other sites

*Answer:* Trying username and password pairs leaked from other sites. Defend with MFA, rate limits and breach checks.
