Skip to content

Archive

Authentication Security

6 articles
Cybersecurity 11 Sep 2026 10 min read

Verify Account Email Changes Before Trusting the New Address

Changing an account’s email address looks like an ordinary profile update. In many systems, though, that address is also used for password resets, security notifications, sign-in links, or account recovery. Replacing it immediately can therefore change who controls a recovery channel. The practical problem is simple: a new email address is only a claim until the application proves that the account holder can receive mail there. If the application treats the claim as trusted too early, a stolen session, typing mistake, or unsafe update flow can redirect security-sensitive messages to the wrong mailbox.

Cybersecurity 11 Sep 2026 10 min read

Treat Recovery Codes as One-Time Authentication Secrets

Multi-factor authentication can lock out a legitimate user when a phone is lost, an authenticator is reset, or a security key is unavailable. Recovery codes give the user a controlled fallback. The risk is that this fallback can quietly become an easier way into the account than the authentication method it is supposed to recover. A recovery code is not just a convenience string. It is an authentication secret that may let someone bypass an unavailable factor. If an attacker obtains a valid code and the application accepts it, the application cannot tell that the person presenting it is not the legitimate user.

Cybersecurity 11 Sep 2026 8 min read

Pin JWT Verification to Approved Algorithms

A JSON Web Token can carry identity and authorization claims across service boundaries. Its compact format also carries a header that describes cryptographic processing, including an alg field. That field comes from the token itself. It is attacker-controlled input until verification succeeds. A verifier therefore must not treat alg as permission to select any cryptographic mode a library happens to support. The application must decide which algorithm, key type, issuer, audience, and other verification rules are acceptable. The token may identify a candidate within that fixed policy, but it must not define the policy.

Cybersecurity 11 Sep 2026 10 min read

Do Not Build Security Links from Untrusted Host Headers

Applications often need to send absolute URLs. A password reset email, account verification message, or administrative invitation needs a link such as https://accounts.example/reset?..., not just /reset?.... A tempting implementation takes the hostname from the current HTTP request and attaches the security-sensitive path. That works in ordinary testing, but it confuses two different facts: where the request says it was addressed and which public origin the application trusts for security links. If an untrusted request can influence the first value, it may influence a link containing a secret token.

Cybersecurity 04 Sep 2026 11 min read

Rotate Session Identifiers After Authentication

A web application often creates a session before a user signs in. The session may hold a shopping cart, a language preference, or state needed during an authentication flow. After login, it is tempting to keep the same session identifier and simply mark that session as authenticated. That creates a security problem if someone else already knows or influenced the pre-login identifier. Authentication has increased what the session is allowed to do, but the credential used to refer to that session has not changed. A previously low-value identifier may suddenly become a key to an authenticated account.

Cybersecurity 04 Sep 2026 10 min read

Design Rate Limits Around Security Identities

A rate limit sounds simple: allow only a certain number of requests during a period. The difficult security question is not the number. It is what you count together. Suppose a login endpoint allows five failed attempts per minute from each IP address. That can slow one client, but an attacker using many addresses can still make many guesses against the same account. Change the rule to five failures per account and another problem appears: anyone who knows a username may be able to keep that user’s account throttled.