Authentication Fundamentals

A track of P54 · Authentication & Kerberos.

Passwords done right — slow hashing, rate limiting against brute force, MFA factors and their failure modes, and the account-recovery soft underbelly.

Two companies leak their user table on the same day. The first stored passwords as unsalted SHA-256; within hours, commodity hardware has recovered most of them by hashing candidate passwords at billions of guesses per second and matching. The second used a deliberately slow, salted password hash; the same attacker, with the same hardware, gets almost nowhere. Identical incident, wildly different outcome, and the whole difference was decided by a one-line choice made long before the breach. This track is about making those choices knowingly.

It begins with the credential at rest. Salting defeats precomputed tables and makes each password an independent problem; a work factor makes each guess expensive on purpose, which is the exact opposite of what you want from the hash in P52's integrity track and the reason a password hash is a different tool with a different job. Then the online side, where the attacker is not cracking a dump but guessing against your live endpoint: rate limiting and lockout turn an unlimited guessing game into a bounded one, with the design tension that a lockout too aggressive becomes a denial-of-service against your own users.

The last two parts are the ones most often skipped. Multi-factor authentication is not one thing — something you know, have, or are — and each factor has its own failure mode, which is why SMS codes and push approvals are not interchangeable with a hardware key when the threat is a determined phisher. And account recovery is where the whole edifice is often quietly undone: a reset token that is guessable, long-lived, or compared in variable time hands over accounts regardless of how carefully the password was stored. You will treat recovery as a first-class authentication path, because that is exactly how an attacker treats it.

Storesalted and slow on purposeThrottlebound the online guessingSecond factorknow, have, areRecoverthe other front door
Four decisions that together determine what a leaked database or a determined guesser actually gets.
Authentication Fundamentals — TransformerLab