Session

Designing Secure Authentication: What Happens Beyond the Login Form

Designing Secure Authentication: What Happens Beyond the Login Form

Every application needs authentication — but secure authentication is more than hashing a password and issuing a token. It's about designing the entire user journey thoughtfully: registration, login, error messaging, password resets, and recovery.

If you're building or maintaining any application with a login screen — regardless of language or framework — this session is for you. We explore the real-world decisions developers make when building authentication systems: proper password hashing (and why encryption isn't enough), practical password policies, defending against user enumeration, secure reset flows, and integrating with password managers. Through practical examples, we examine how small design choices strengthen or weaken an application's security posture.

You'll leave with a checklist you can run against your own login flow, and specific, actionable changes to make — no framework required.

Johnie Karr

Sr. Software Engineer, Hygiena

London, Kentucky, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top