Week 02 · reflection

Week 2 Reflection: Where Does Authentication Actually Fail?

Use your Authentication Architecture and password-defense work.

Write 150 to 250 words, or record an equivalent explanation, responding to this prompt:

A system requires a long password, so its designer claims the account is secure. What important parts of authentication are missing from that claim?

Include:

  • one risk involving password reuse, phishing, or credential exposure
  • one reason MFA may reduce risk
  • one weakness that can exist in account recovery
  • the difference between authentication and authorization
  • one observation from your hash/salt activity
  • one trade-off from your final authentication design

Finish with:

If I could improve only one part of the authentication system first, I would change ________ because ________.

Do not include real passwords, real recovery information, or personal account details.