Best practices for login pages?

前端 未结 12 1969
后悔当初
后悔当初 2021-01-31 19:30

I am working on a single sign-on login page using Shibboleth that will be used for a variety of web applications. Obviously we would like to make this page as secure and usable

12条回答
  •  庸人自扰
    2021-01-31 20:02

    Seems like a no-brainer, but use HTTPS if the app requires it. Heck, even if it doesn't warrant it because people tend to reuse the same passwords. You can get a SSL cert cheap these days. If they lift a password from your site they can try it elsewhere. Even many banks don't have the login page on a secure line. It posts to an HTTPS page, but there is still no protection of a man in the middle type attack.

    I agree with Omniwombat. Phishing is a hard problem to solve well and seemingly impossible to solve it completely.

提交回复
热议问题