Guided pathThis is part of Understand security: protocols, identity and secure architectureBack to the path

Passwords done right

P54.authn-fundamentals.01 · Audience: guest, it-ml, language-pro · Prerequisites: Hashing: fingerprints of data

Real LLM grading for this pageLLM grading (this page):

Welcome to Authentication & Kerberos — proving who you are, the counterpart to P55's delegated authorization. Hashing a password well (P52) is necessary but not sufficient: an attacker who can guess forever will get in. This track starts with the everyday defences — rate limiting, MFA, and safe account recovery.

Same thread as every module here: concept → protocol → attack → defence. The graded work is always the defence — here, throttling the login endpoint against brute force.

The code runs entirely in your browser (Pyodide); nothing leaves your machine.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — rate-limit the login endpoint

Loading exercise…

Interview rung — MFA & account recovery (free-form)

Loading exercise…

My notes on this module

Loading your notes...

Passwords done right — TransformerLab