Protect Accounts with Practical Authentication
Apply password hashing, multi-factor authentication, secure sessions, rate limits, and recovery safeguards.
Explanation
Authentication establishes whether a user controls an expected account. Secure systems store password verifiers with modern password-hashing functions, protect session identifiers, limit repeated attempts, and offer carefully designed recovery.
Students review an insecure login design, identify weaknesses, and propose a layered authentication flow. The discussion includes usability, administrator access, logging, and recovery abuse.
Learning activities
- Review an insecure login flow and list its weaknesses.
- Design a layered authentication and recovery process.
- Explain how secure cookies protect a session.
Code example
php
$hash = password_hash($password, PASSWORD_DEFAULT);
if (password_verify($submittedPassword, $hash)) {
session_regenerate_id(true);
}Knowledge check
1. How should application passwords be stored?
- With a password-hashing function
- As plain text
- Inside HTML
Show answer
With a password-hashing function