References and Further Reading
Usernames
Authentication - OWASP Cheat Sheet Series
Passwords
How long should a password be in 2023? You're asking the wrong question | ZDNET
Are Your Passwords in the Green in 2023? (hivesystems.com)
Multi-factor Authentication
Do you use SMS for two-factor authentication? Don't. (cnet.com)
United Airlines uses multiple-choice security questions. (slate.com)
Security Questions
How Common Security Questions Can Pose a High Risk | BeyondTrust
"Forgot Login" Flows
Forgot Password - OWASP Cheat Sheet Series
Passkeys
Passkeys (Passkey Authentication) (fidoalliance.org)
Passkeys may not be for you, but they are safe and easy—here’s why | Ars Technica
Big Tech passkey implementations are a trap | Proton
Identity Theft
Most People Shouldn’t Pay for Identity Theft Protection | Reviews by Wirecutter (nytimes.com)
14 Ways Scammers Can Steal Your Credit Card Numbers in 2024 (aura.com)