Skip to main content

Password Authentication

Evaluate password verification, storage, throttling, compromised values, phishing, reuse, and recovery as one control.

Control objective

Password authentication verifies knowledge of a memorized secret without storing or exposing the plaintext value. It must limit online guessing, detect known compromised values, protect stored verifiers, and provide recovery that does not bypass the required assurance.

Verification and storage

Use a salted password hashing scheme with a work factor selected for the environment. Protect the verifier store and rate-limit failed attempts by account, source, and broader abuse signals without making account denial easy. Compare proposed passwords against compromised-value blocklists. Permit password managers and paste.

Attack paths

Credential stuffing reuses breached username-password pairs. Password spraying tries common values across accounts. Phishing captures a secret through a false verifier. Offline cracking attacks stolen verifiers. Session theft bypasses the password ceremony. MFA fatigue and weak recovery can bypass added factors.

Failure and residual risk

Complex composition rules can produce predictable changes and user workarounds. Frequent forced changes do not help without evidence of compromise. Lockouts can create denial of service. A strong password remains replayable at a false verifier and across reused sites.

Pomerium boundary

Pomerium normally delegates human authentication to a configured identity provider. The provider owns password verification, storage, throttling, compromised-value checks, MFA, and recovery. Pomerium consumes the resulting identity and cannot make a weak upstream password ceremony phishing-resistant.

Evaluation checklist

  • Are plaintext passwords absent from storage, logs, transport, and support tools?
  • Does the verifier use a salted, expensive password hashing scheme?
  • Are stuffing, spraying, online guessing, and offline cracking addressed separately?
  • Do MFA and recovery resist phishing and social engineering?
  • Can compromised accounts and sessions be contained without unsafe global lockout?

Sources and further reading

Keep learning

Identity and Authentication

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Learn this term
Identity and Authentication

Account Recovery

Restore account access without giving attackers an easier path than the normal authentication and enrollment process.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo