Explore a conference talk on implementing "stealth" authentication techniques to enhance web application security. Learn how to prevent information leakage during authentication processes, potentially thwarting hackers' attempts to exploit vulnerabilities. Discover the OWASP Top 10 security risks, upfront web application security measures, and strong authentication methods like OTP and challenge-response. Examine practical examples of implementing two-factor authentication, simulating second factors for unknown users, and handling account lockouts securely. Gain insights into usability considerations, configuration options, and strategies to prevent hidden information channels. Enhance your understanding of advanced authentication security practices to better protect web applications from potential threats.
Stealth Authentication: Preventing Information Leaks in Web Application Security - APPSEC CA 2017