पाठ 3 / 25
Threat Model for Login
How attackers actually get in.
The usual suspects
Credential stuffing replays username/password pairs leaked from other sites, exploiting password reuse; it is automated and distributed across many IPs. Password spraying tries a few common passwords against many accounts to dodge lockouts. Phishing tricks users into typing credentials (and even one-time codes) into a look-alike site, often relayed in real time. Session hijacking steals a session cookie or token (through XSS, malware or an insecure network) so the attacker never needs the password. Account enumeration uses differing error messages or timings to learn which emails are registered. Defences layer up: breached-password checks, rate limiting, MFA, phishing-resistant passkeys, hardened cookies and uniform responses.
Threats and primary defences
A quick reference.
threat primary defences
------ ----------------
credential stuffing MFA, breached-password checks, bot detection, rate limits
password spraying rate limits per account AND per source, MFA, monitoring
phishing passkeys / WebAuthn (origin-bound), user education
session hijacking HttpOnly+Secure cookies, XSS prevention, short sessions
account enumeration generic errors, same response for known/unknown users
brute force slow hashing, throttling, progressive delaysAssume passwords are already leaked
Design as if attackers hold a large list of real credentials. Controls that only work when passwords are secret are not enough on their own.
त्वरित जाँच: Which factor resists real-time phishing best?
- A longer password
- An SMS one-time code
- A TOTP code from an app
- A passkey (WebAuthn credential) bound to the site origin
Answer
A passkey (WebAuthn credential) bound to the site origin — WebAuthn signatures are bound to the origin, so a look-alike domain cannot use them.