API2:2023
Broken Authentication
Slide 18 of 28
Part 4 · Prevention
Slide 18
PART 4
Prevention
Slides 18–26 · Seven mitigations + the full picture
Slide 18 · Prevention Overview
Seven ways to fix broken authentication.
Each one closes a different attack vector. None is sufficient alone.
📖
MIT 01 — Use Proven Standards
OAuth 2.0, OpenID Connect. Never build custom auth from scratch.
🚫
MIT 02 — Rate Limit + Lock Out
Limit login attempts per IP, per account. Add CAPTCHA. Count at the right layer.
📱
MIT 03 — Multi-Factor Authentication
A stolen password isn't enough. A second factor stops credential stuffing cold.
🆔
MIT 04 — Validate Tokens Properly
Verify signature, algorithm, expiry. Never accept alg:none. Short-lived tokens only.
🔒
MIT 05 — Secure Credential Storage
bcrypt or Argon2 for passwords. Never MD5 or SHA-1. Salted, stretched hashes.
🔄
MIT 06 — Re-auth for Sensitive Operations
Email, password, MFA, payment changes require current password confirmation.
🚫
MIT 07 — Never Tokens in URLs
Tokens belong in headers. URLs end up in logs, history, and referrer headers.
← Back
MIT 01: Use proven standards →