Web Security: User Authentication and Access Control
1h 6mIntermediate2023-10-25
Authors

Kevin Skoglund
Founder of NovaFabrica
Course details
User authentication plays a central role in almost everything we do online, but there are many big security pitfalls to avoid. From apps to hardware and websites, user accounts and logins are everywhere. Authentication is critical for verifying a user's identity online and for confirming permissions so individuals can perform privileged actions. In this course, instructor Kevin Skoglund teaches you how authentication works and how to implement it correctly when building web applications. Kevin takes you through some of the most common attacks, and shows you how to protect your site. He also demonstrates how to secure your own passwords and digital identity so you can work securely. This course is ideal for all developers, particularly those who are interested in authentication and security.
Skills covered
Software Development SecurityIdentity and Access ManagementCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - Verify identity and access privileges
1. User Authentication
- 02 - The importance of authentication
- 03 - Authentication factors
- 04 - Credentials
- 05 - Multi-factor authentication
- 06 - Pitfalls of multi-factor authentication
- 07 - Biomertric authentication
2. Passwords
- 08 - Password hashing
- 09 - Brute force attacks
- 10 - Speed and throttling
- 11 - Dictionary attacks
- 12 - Salted passwords
- 13 - Strong passwords and password managers
3. Managing User Passwords
- 14 - Password requirements
- 15 - Password theft and reuse
- 16 - Handle forgotten passwords
4. Access Control
- 17 - Insecure references
- 18 - Regulating access privileges
- 19 - Cookies and sessions
- 20 - Deny lists and geofilters
- 21 - Single sign-on services
Conclusion
- 22 - Next steps