Control objective
Password authentication verifies knowledge of a memorized secret without storing or exposing the plaintext value. It must limit online guessing, detect known compromised values, protect stored verifiers, and provide recovery that does not bypass the required assurance.
Verification and storage
Use a salted password hashing scheme with a work factor selected for the environment. Protect the verifier store and rate-limit failed attempts by account, source, and broader abuse signals without making account denial easy. Compare proposed passwords against compromised-value blocklists. Permit password managers and paste.
Attack paths
Credential stuffing reuses breached username-password pairs. Password spraying tries common values across accounts. Phishing captures a secret through a false verifier. Offline cracking attacks stolen verifiers. Session theft bypasses the password ceremony. MFA fatigue and weak recovery can bypass added factors.
Failure and residual risk
Complex composition rules can produce predictable changes and user workarounds. Frequent forced changes do not help without evidence of compromise. Lockouts can create denial of service. A strong password remains replayable at a false verifier and across reused sites.
Pomerium boundary
Pomerium normally delegates human authentication to a configured identity provider. The provider owns password verification, storage, throttling, compromised-value checks, MFA, and recovery. Pomerium consumes the resulting identity and cannot make a weak upstream password ceremony phishing-resistant.
Evaluation checklist
- Are plaintext passwords absent from storage, logs, transport, and support tools?
- Does the verifier use a salted, expensive password hashing scheme?
- Are stuffing, spraying, online guessing, and offline cracking addressed separately?
- Do MFA and recovery resist phishing and social engineering?
- Can compromised accounts and sessions be contained without unsafe global lockout?
