पाठ 19 / 25

Authentication Failures

Credential stuffing, weak recovery, missing MFA.

Make account takeover hard

Common authentication failures: permitting weak or breached passwords, no protection against automated credential stuffing and brute force, user enumeration through different error messages, weak password recovery (guessable questions, long-lived reset links), and no multi-factor authentication (MFA). Defences: offer phishing-resistant MFA (passkeys/WebAuthn) or at least TOTP, rate limit and detect suspicious logins, use generic error messages, make reset tokens single-use and short-lived, and prefer a proven identity provider over custom code.

Know who users are, notice attacks

Robust authentication and sessions keep accounts safe; logging and monitoring detect attacks in progress.

Three ideas: authentication, sessions and tokens, logging and monitoring.
Figure 7.1 — Authentication, sessions and monitoring.

Login hardening checklist

Controls for a login and recovery flow.

- generic message: "Invalid email or password" for both unknown user and wrong password
- rate limit per account and per IP; exponential backoff; alert on spikes
- breached-password check at sign-up and password change
- MFA available (passkeys preferred), required for admins
- reset tokens: random, single-use, expire in ~15-60 minutes, invalidated after password change
- notify users of new sign-ins and security changes

Prefer passkeys

WebAuthn passkeys are bound to the site's origin, so they resist phishing far better than passwords plus SMS codes.

त्वरित जाँच: What is credential stuffing?

  • Filling a form automatically for accessibility
  • Storing too many passwords
  • Encrypting credentials twice
  • Trying username and password pairs leaked from other sites
Answer

Trying username and password pairs leaked from other sites — Defend with MFA, rate limits and breach checks.