Home/Blog/Cheat Sheets
Cheat Sheets

Cheat Sheet Series: Authentication

A practical reading of the OWASP Authentication Cheat Sheet. Accept a long secret, store it so a breach does not reveal it, and make a stolen password useless on its own.

Primary source: OWASP Authentication Cheat Sheet. Store secrets as in the Password Storage Cheat Sheet, and sessions as in the Session Management Cheat Sheet.

A password that follows the rules can still be in a breach list. A second factor matters more than a required symbol.

The secret

TopicKey points
LengthRequire at least 8 characters, and allow at least 64. Do not set a short maximum. Spaces and passphrases are valid passwords.
CompositionDo not require a digit, a symbol or mixed case. Those rules push people into predictable patterns.
Breached passwordsCheck a new or changed password against a breached-password list and reject a match.
RotationDo not force a change on a timer. Require a change when you have evidence the password was exposed.
PasteAllow paste and password managers. Blocking them pushes people onto shorter secrets.
StorageHash with Argon2id, bcrypt or scrypt and a unique salt. A fast hash, or reversible encryption, is not password storage.
RecoverySend a short-lived, single-use link. Never email the current password, and do not reveal whether the account exists.
HintsDo not offer a password hint or a security question. Both are extra secrets that are easy to guess.

Login and session

TopicKey points
ErrorsUse the same message, and a similar response time, for an unknown user and a wrong password.
MFAPrefer a passkey or WebAuthn. An authenticator app is the next choice. SMS is a fallback, not the design.
Step-upAsk for the second factor again before a password, email or payment change.
ThrottlingSlow repeated failures. A hard lock after a few tries lets someone freeze the account.
New sessionIssue a new session identifier when login succeeds. Do not keep the identifier from before login.
CookieSet Secure, HttpOnly and SameSite. Do not put the session identifier in the URL.
LogoutInvalidate the session on the server. Clearing the cookie in the browser is not logout.
AdminKeep administration behind a stronger factor, and expire that session sooner than a normal one.

What a test should show

  • A breached password is rejected when it is set and when it is changed.
  • An unknown user and a wrong password return the same message.
  • Login replaces the session identifier, and logout invalidates it on the server.
  • The session cookie is Secure, HttpOnly and SameSite.
  • A password or email change asks for the current factor again.
  • Stored passwords are salted adaptive hashes.
#cheat-sheet#authentication#owasp

Ready to strengthen your security?

Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.