<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Talk%3AAuthentication_Cheat_Sheet</id>
		<title>Talk:Authentication Cheat Sheet - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Talk%3AAuthentication_Cheat_Sheet"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Authentication_Cheat_Sheet&amp;action=history"/>
		<updated>2026-04-28T18:26:31Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Authentication_Cheat_Sheet&amp;diff=242688&amp;oldid=prev</id>
		<title>Gunnar Guðvarðarson: NIST Special Publication 800-63B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Authentication_Cheat_Sheet&amp;diff=242688&amp;oldid=prev"/>
				<updated>2018-08-21T13:15:30Z</updated>
		
		<summary type="html">&lt;p&gt;NIST Special Publication 800-63B&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 13:15, 21 August 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l35&quot; &gt;Line 35:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 35:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Sven Neuhaus|Sven Neuhaus]] ([[User talk:Sven Neuhaus|talk]]) 03:48, 6 February 2015 (CST)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[User:Sven Neuhaus|Sven Neuhaus]] ([[User talk:Sven Neuhaus|talk]]) 03:48, 6 February 2015 (CST)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;=== Adapting the password complexity section to conform to NIST Special Publication 800-63B ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;I'd like to suggest replacing the password complexity section with [https://pages.nist.gov/800-63-3/sp800-63b.html#appA Appendix A of NIST Special Publication 800-63B]. [[User:Gunnar Guðvarðarson|Gunnar Guðvarðarson]] ([[User talk:Gunnar Guðvarðarson|talk]]) 08:15, 21 August 2018 (CDT)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Gunnar Guðvarðarson</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Authentication_Cheat_Sheet&amp;diff=189136&amp;oldid=prev</id>
		<title>Sven Neuhaus: some suggestions</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Authentication_Cheat_Sheet&amp;diff=189136&amp;oldid=prev"/>
				<updated>2015-02-06T09:48:32Z</updated>
		
		<summary type="html">&lt;p&gt;some suggestions&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;I have a few suggestions for this page:&lt;br /&gt;
&lt;br /&gt;
=== General Guidelines ===&lt;br /&gt;
==== User IDs ====&lt;br /&gt;
===== Email address as a User ID =====&lt;br /&gt;
====== Validation ======&lt;br /&gt;
&lt;br /&gt;
&amp;quot;To ensure an address is deliverable, the only way to check this is to send the user an email and have the user take action to confirm receipt.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Another, less obtrusive way of making sure an email address is deliverable is to use the &amp;quot;RCPT TO&amp;quot; command during a SMTP dialogue and making sure you get a &amp;quot;250&amp;quot; or &amp;quot;251&amp;quot; response. There may be a temporary error if the server uses greylisting.&lt;br /&gt;
&lt;br /&gt;
=== Password length ===&lt;br /&gt;
&lt;br /&gt;
Why is there the recommendation of having a maximum password length of 128?&lt;br /&gt;
&lt;br /&gt;
=== Password complexity ===&lt;br /&gt;
&lt;br /&gt;
This should mention UTF-8 characters, making sure they are legal to enter.&lt;br /&gt;
&lt;br /&gt;
=== Utilize Multi-Factor Authentication ===&lt;br /&gt;
&lt;br /&gt;
This should mention receiving the token via SMS as it is a separate channel (not the internet),&lt;br /&gt;
which provides security benefits.&lt;br /&gt;
&lt;br /&gt;
=== Authentication and Error Messages ===&lt;br /&gt;
==== Correct Response Example ====&lt;br /&gt;
&lt;br /&gt;
If the response doesn't specify whether the username is wrong (does not exist) or the password,&lt;br /&gt;
that is an inconvenience for the user, especially if she/he doesn't notice the error.&lt;br /&gt;
Many times, there is an alternative way of finding valid usernames anyway, so there is no additional security gained. Use good judgement.&lt;br /&gt;
&lt;br /&gt;
=== Use of authentication protocols that require no password ===&lt;br /&gt;
&lt;br /&gt;
Mozilla Persona is missing in this list, it seems to be the best solution in terms of privacy, its only problem is a lack of adoption, something this cheat sheet could change.&lt;br /&gt;
&lt;br /&gt;
[[User:Sven Neuhaus|Sven Neuhaus]] ([[User talk:Sven Neuhaus|talk]]) 03:48, 6 February 2015 (CST)&lt;/div&gt;</summary>
		<author><name>Sven Neuhaus</name></author>	</entry>

	</feed>