ContentsThe library

Proving Who You Are

What Each Kind of Proof Actually Resists

Last timeThree Questions, Often Confused

Passwords, emailed codes, authenticator apps and hardware keys are not stronger and weaker versions of one thing. Each resists a different attack and assumes something different.

Judging a proof by the attack

The usual way of talking about sign-in methods puts them on a line from weak

to strong. It is the wrong shape. Each method resists some attacks

completely and others not at all, and knowing which is which is more useful

than a ranking.

Four attacks cover nearly everything.

Guessing, where somebody tries values until one works, either against one

account or against millions of accounts with one common password.

Reuse, where a password leaked from an unrelated site is tried against

yours. The user did nothing wrong at your site and your site did nothing

wrong either.

Interception, where the proof is read in transit or read out of a log or a

screenshot.

And handing it over, where a convincing fake site asks the user for the

proof and they supply it, because it looks exactly like signing in. This is

the one that produces most of the real losses, and it is the one most

methods do nothing about.

FIG 1Which attack each method actually resists
resists guessingresists a leaked passworresists interceptionresists a convincing fak
a short password0000
a long unique password1000
password plus emailed co1100
password plus app code1110
password plus push appro1110
a hardware key1111
a passkey on the device1111
The last column is nearly empty and it is the column that matters most. The two marks sit either side of the line: a push approval looks like the strongest thing a user can be given and still fails there, while a hardware key is the first row where the column turns on. Everything above that line depends on the user correctly judging the site.

A secret the user remembers

A password resists guessing, and only if it is long. The arithmetic is worth

stating because it is the only part of this that behaves well.

FIG 2How large the guessing space is
number of possible values
characters available in each position
length of the secret
Length is in the exponent and the alphabet is in the base, which is why adding characters beats adding symbol classes by a wide margin. A twelve-character password from a 72-character set has about 20 million times the space of an eight-character one, and this is the entire protection a password offers.

Against everything else it offers nothing, and the gap is not technical, it

is behavioural. A password is only unique to your site if the user made it

unique, and most people do not. So a leak anywhere becomes a leak

everywhere, and the attacker does not guess at all, they simply try the

known password with the known email address.

That assumption, that the user behaves in a way almost nobody behaves, is

the real weakness. It is also why the standard advice changed: long

passphrases rather than enforced symbol classes, a check against known

leaked passwords at the point of setting one, and no routine expiry, since

forced rotation produces predictable variations rather than new secrets.

Three things are your responsibility on the storage side, and they belong in

a different course on how a password is stored. Here it is enough to say

that the password must never be recoverable from what you hold, which rules

out encrypting it and rules out any design where somebody can be emailed

their existing password.

The lesson stops here

5 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Who You Are, What You May Do, and Who Remembers
  2. 02What Each Kind of Proof Actually Resistsyou are here
  3. 03The Thing the Browser Carriesopening only
  4. 04The Token That Answers for Itselfopening only
  5. 05Two Tokens Beat Oneopening only
  6. 06Borrowing Somebody Elses Proofopening only
  7. 07The Request Your Browser Sent for Somebody Elseopening only
  8. 08Making Somebody Stop Being Signed Inopening only

Read alongside