Designing a secure login system is hard
I know from my past experience that designing a secure login system is hard, but I was forced to look into it recently as I was trying to build something as a side project. The article provides a good overview of the various systems that needs to be implemented
- Secure password storage
- Long term persistent authentication
- Account recovery
- Store hashes of password in the database, but don't use broken hashes like MD5 and SHA1.
- The suggested "acceptable" password hashing algorithms are Argon2, bcrypt, scrypt and PBKDF2.
- Use dropbox's zxcvbn to estimate the strength of the password and only accept passwords of sufficient strength.
- It is easy to end up with insufficient randomness so use the proper ways to generate random numbers! On this note, I always run into performance issues regarding randomness (such as lock contention in urandom_read for security purposes).
- Timing attacks -- string comparison of authentication token may result in the attacker guessing which character in the authentication token is wrong. The solution to this is to store the hash of the authentication token and compare the hashes.
- Rate limit things! This will help if the attacker is going to brute force his way.
- Reseting password is a backdoor access and it is scary to implement one yourself.
- Integration with Facebook login or Google Identity platform
- Generation of authentication token and storage of it (database on the server and cookie on the client)
- Verification of authentication token
Labels: programming, stupid people in the world
