A practical reading of the OWASP Authentication Cheat Sheet. Accept a long secret, store it so a breach does not reveal it, and make a stolen password useless on its own.
Primary source: OWASP Authentication Cheat Sheet. Store secrets as in the Password Storage Cheat Sheet, and sessions as in the Session Management Cheat Sheet.
A password that follows the rules can still be in a breach list. A second factor matters more than a required symbol.
The secret
| Topic | Key points |
|---|---|
| Length | Require at least 8 characters, and allow at least 64. Do not set a short maximum. Spaces and passphrases are valid passwords. |
| Composition | Do not require a digit, a symbol or mixed case. Those rules push people into predictable patterns. |
| Breached passwords | Check a new or changed password against a breached-password list and reject a match. |
| Rotation | Do not force a change on a timer. Require a change when you have evidence the password was exposed. |
| Paste | Allow paste and password managers. Blocking them pushes people onto shorter secrets. |
| Storage | Hash with Argon2id, bcrypt or scrypt and a unique salt. A fast hash, or reversible encryption, is not password storage. |
| Recovery | Send a short-lived, single-use link. Never email the current password, and do not reveal whether the account exists. |
| Hints | Do not offer a password hint or a security question. Both are extra secrets that are easy to guess. |
Login and session
| Topic | Key points |
|---|---|
| Errors | Use the same message, and a similar response time, for an unknown user and a wrong password. |
| MFA | Prefer a passkey or WebAuthn. An authenticator app is the next choice. SMS is a fallback, not the design. |
| Step-up | Ask for the second factor again before a password, email or payment change. |
| Throttling | Slow repeated failures. A hard lock after a few tries lets someone freeze the account. |
| New session | Issue a new session identifier when login succeeds. Do not keep the identifier from before login. |
| Cookie | Set Secure, HttpOnly and SameSite. Do not put the session identifier in the URL. |
| Logout | Invalidate the session on the server. Clearing the cookie in the browser is not logout. |
| Admin | Keep administration behind a stronger factor, and expire that session sooner than a normal one. |
What a test should show
- A breached password is rejected when it is set and when it is changed.
- An unknown user and a wrong password return the same message.
- Login replaces the session identifier, and logout invalidates it on the server.
- The session cookie is Secure, HttpOnly and SameSite.
- A password or email change asks for the current factor again.
- Stored passwords are salted adaptive hashes.
Ready to strengthen your security?
Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.