Password-based authentication verifies user identity by matching a secret string provided at login against a stored verifier. It is simple and widely deployed but requires careful handling of storage, strength policies and recovery flows to mitigate compromise and usability trade-offs. Organizations must enforce length, hashing and monitoring policies.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Password-based authentication checks a claimed identity against a secret password that should be known only to the user and the authenticating service.
Passwords are an early and still widespread knowledge factor. NIST SP 800-63B specifies requirements for storage, rate limiting, and handling of authenticator secrets.
A password is a shared secret: the user proves knowledge and the service compares safely derived values. If the secret is copied or guessed, this factor alone no longer protects the account.
Authentication relies on knowledge that only the authorized person should possess.
The service stores a suitable derivation and verifies input without needing the plaintext password.
Length, rate limiting, and safe storage make guessing and theft harder.
Passwords remain practical but are exposed to phishing, reuse, and brute force. High-risk access should add strong methods such as MFA or passwordless authentication.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.