Registration of New UsersPreventing Automated RegistrationThe Basic Flow of the Login Process and Session ManagementLogin Workflow Step 1: Anonymous Session Created on First HitLogin Workflow Step 2: Starting HTTPS and Encryption in TransitLogin Workflow Step 3: Processing and Verifying CredentialsLogin Workflow Step 4: Start the User’s Authenticated SessionLogin Workflow Step 5: Do Cool ThingsLogin Workflow Step 6: Potential Re-Authentication for Sensitive OperationsLogin Workflow Step 7: Idle TimeoutLogin Workflow Step 8: Absolute TimeoutLogin Workflow Step 9: LogoutAttacks Against AuthenticationSession HijackingSession FixationSecure Cookie Properties for Session ManagementDangers of Storing Sensitive Data in CookiesCredential SecurityPassword PolicyPassword ManagersPassword Storage: Verify but Not RecoverForgot Password WorkflowUsername HarvestingBrute Force Attacks, Account Lockout, and Multi-Factor RevisitedRemember Me FeatureMulti-Factor AuthenticationSeed StorageWhere Do You Send the Token?Federated Identity and SAMLOAuth BasicsAdditional ReadingSummary