Session
Designing Secure Authentication: What Happens Beyond the Login Form
Designing Secure Authentication: What Happens Beyond the Login Form
Every application needs authentication — but secure authentication is more than hashing a password and issuing a token. It's about designing the entire user journey thoughtfully: registration, login, error messaging, password resets, and recovery.
If you're building or maintaining any application with a login screen — regardless of language or framework — this session is for you. We explore the real-world decisions developers make when building authentication systems: proper password hashing (and why encryption isn't enough), practical password policies, defending against user enumeration, secure reset flows, and integrating with password managers. Through practical examples, we examine how small design choices strengthen or weaken an application's security posture.
You'll leave with a checklist you can run against your own login flow, and specific, actionable changes to make — no framework required.
Johnie Karr
Sr. Software Engineer, Hygiena
London, Kentucky, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top