Week 02 · reflection
Week 2 Reflection: Where Does Authentication Actually Fail?
Use your Authentication Architecture and password-defense work.
Write 150 to 250 words, or record an equivalent explanation, responding to this prompt:
A system requires a long password, so its designer claims the account is secure. What important parts of authentication are missing from that claim?
Include:
- one risk involving password reuse, phishing, or credential exposure
- one reason MFA may reduce risk
- one weakness that can exist in account recovery
- the difference between authentication and authorization
- one observation from your hash/salt activity
- one trade-off from your final authentication design
Finish with:
If I could improve only one part of the authentication system first, I would change ________ because ________.
Do not include real passwords, real recovery information, or personal account details.