

0 / 2 embers
0 / 3000 xp
click for more info
Complete a lesson to start your streak
click for more info
Still calibrating
click for more info
Not enough gems
Cost: 6 gems
1: Authentication
incomplete
2: Stateless vs. Stateful Authentication
incomplete
3: What Are Sessions?
incomplete
4: What Are Cookies?
incomplete
5: Cookie Security
incomplete
6: Session Lifetime
incomplete
7: Password Resets
incomplete
8: Broken Password Reset Flow
incomplete
9: OAuth 2.0
incomplete
10: SAML and OIDC
incomplete
11: API Keys
incomplete
12: Reauthentication
incomplete
13: Authentication Misconceptions
incomplete
Back
ctrl+,
Next
ctrl+.
This lesson's interactive features are locked, please to keep using them
Many password rules you've encountered in the wild are, unfortunately, just security theater. They add friction without stopping how attackers guess and reuse passwords. For example, "change your password every 90 days" may sound secure, but users usually just make predictable changes:
OtterRiver1!OtterRiver2!OtterRiver3!Current NIST password guidance says not to require periodic password changes. Only force a change when there's evidence the password has been compromised!
The silly game of "Your password must include uppercase and lowercase letters, numbers, and symbols" leads to passwords like Password1!.
Humans are predictable, and given simple rules, we follow patterns:
@ for a, 3 for e)Attackers know this! Password crackers are built around these patterns. It's way better to prioritize length, block known-compromised passwords, and support password managers. A randomly generated passphrase can be easier to remember while still being hard to guess.
"What was your first pet's name?" is not effective authentication. These kinds of questions are:
They're just recovery vulnerabilities disguised as security features.