Back to list
igbuend

password-based-authentication

by igbuend

A repository of security related skills - like secure code review and pentesting - for Claude and other AI.

2🍴 1📅 Jan 24, 2026

SKILL.md


name: password-based-authentication description: Security pattern for implementing password-based authentication. Use when designing login systems with username/password, implementing password storage, hashing, salting, peppering, password policies, or password reset flows. Specialization of the Authentication pattern.

Password-Based Authentication Security Pattern

A subject proves identity by providing a correct identifier (username/email) and corresponding password. Relies on the assumption that only the actual owner knows the correct password.

Core Components

RoleTypeResponsibility
SubjectEntityProvides identifier and password
EnforcerEnforcement PointEnsures authentication before action processing
Verification ManagerEntityCollects inputs for password verification
ComparatorDecision PointCompares hash values
HasherCryptographic PrimitiveCalculates hash values
Password StoreStorageKeeps hash values for registered identities
RegistrarEntityHandles subject registration
ResetterEntityHandles credential reset
Password PolicyInformation PointRules passwords must satisfy
SRNGCryptographic PrimitiveSecure random number generator

Data Elements

  • id: Identifier (username, email)
  • pwd: Password provided by Subject
  • hash(pwd): Hash value of password
  • salt: Random value unique per Subject
  • pepper: System-wide secret for additional protection

Password Hashing

Required Approach

  1. Use modern password hashing algorithms: Argon2, scrypt, bcrypt, or PBKDF2
  2. Never use general-purpose hash functions (MD5, SHA-1, SHA-256) alone
  3. Always use salting (typically automatic with modern algorithms)

Salting

  • Add random string unique per Subject before hashing
  • Ensures identical passwords produce different hashes
  • Salt stored in plaintext alongside hash
  • Modern algorithms handle salt automatically

Peppering (Optional)

  • System-wide secret added before hashing
  • Stored separately from password store
  • Provides additional protection if password store is compromised

Registration Flow

Three approaches for credential determination:

  1. Subject provides identifier and password
  2. Subject provides identifier; Registrar selects password
  3. Registrar selects both identifier and password

Upon completion:

  • Password Store contains: identifier, hash(salted password), salt
  • Subject possesses: identifier and password

Password Policy

Enforce policies including:

  • Minimum/maximum length
  • Character requirements
  • Common password blacklist
  • Breach database checking

Password Reset

  1. Verify Subject identity through out-of-band channel
  2. Generate time-limited reset token
  3. Never reveal whether account exists
  4. Invalidate existing sessions after reset
  5. Force re-authentication

Security Considerations

Password Store Protection

  • Encrypt at rest
  • Restrict access
  • Monitor for breaches
  • Detect tampering

Identifier Security

  • Don't rely on identifier secrecy
  • Prevent enumeration attacks
  • Use consistent timing for valid/invalid identifiers

Verification Timing

  • Use constant-time comparison
  • Prevent timing attacks

Implementation Checklist

  • Using Argon2/scrypt/bcrypt/PBKDF2
  • Automatic salting enabled
  • Password policy enforced
  • Secure reset flow implemented
  • Rate limiting on login attempts
  • Constant-time hash comparison
  • No credential logging

References

Score

Total Score

70/100

Based on repository quality metrics

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

+10
説明文

100文字以上の説明がある

+10
人気

GitHub Stars 100以上

0/15
最近の活動

3ヶ月以内に更新がある

0/10
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

+5
タグ

1つ以上のタグが設定されている

0/5

Reviews

💬

Reviews coming soon