I’m curious, does anyone have any thoughts on how secure this auth library is?
I’ve up till now used FreakAuth, which I’m mainly abandoning because it feels so bloated.
Unfortunatly because I’ve still got a lot to learn about security, I can’t judge much from what I see in the code. One point though, is that I see that limiting of login attempts is cookie based only, doesn’t this basically mean that it has no effect on brute force attacks?
In regards to limiting the number of login attempts to 5. A brute force attack is usually an automated process. Therefore a script running from an external resource would not be able to edit the cookie unless a macro was used along with a cookie editor to reset the attempts to 0. The whole point of having the maximum login attempts is to prevent a brute force attack.
In regards to general security. The Authentication Library was built to be simple and to be secure, if you read through the 3 threads on here and the many many pages of user comments, I haven’t had one comment related to it being insecure or the security to be poor. The remember me function uses a somewhat unique way of authenticating the user using a cookie; this was suggested to em by a user of the first “Fresh Powered Auth Library” and has been implemented in this version.
Hopefully I have answered your questions and I can only apologise for not seeing it and replying to it earlier.
Thanks.