पाठ 19 / 25
Authentication Failures
Credential stuffing, weak recovery, missing MFA.
Make account takeover hard
Common authentication failures: permitting weak or breached passwords, no protection against automated credential stuffing and brute force, user enumeration through different error messages, weak password recovery (guessable questions, long-lived reset links), and no multi-factor authentication (MFA). Defences: offer phishing-resistant MFA (passkeys/WebAuthn) or at least TOTP, rate limit and detect suspicious logins, use generic error messages, make reset tokens single-use and short-lived, and prefer a proven identity provider over custom code.
Know who users are, notice attacks
Robust authentication and sessions keep accounts safe; logging and monitoring detect attacks in progress.
Login hardening checklist
Controls for a login and recovery flow.
- generic message: "Invalid email or password" for both unknown user and wrong password
- rate limit per account and per IP; exponential backoff; alert on spikes
- breached-password check at sign-up and password change
- MFA available (passkeys preferred), required for admins
- reset tokens: random, single-use, expire in ~15-60 minutes, invalidated after password change
- notify users of new sign-ins and security changesPrefer passkeys
WebAuthn passkeys are bound to the site's origin, so they resist phishing far better than passwords plus SMS codes.
त्वरित जाँच: What is credential stuffing?
- Filling a form automatically for accessibility
- Storing too many passwords
- Encrypting credentials twice
- Trying username and password pairs leaked from other sites
Answer
Trying username and password pairs leaked from other sites — Defend with MFA, rate limits and breach checks.