Secure Coding & OWASP Top 10 for Backend · Lektion

Multi-Faktor-Authentifizierung und Kontowiederherstellung

Stärken Sie die Authentifizierung mit MFA über Passwörter hinaus und entwerfen Sie sichere Abläufe zur Kontowiederherstellung, die nicht zu einer Hintertür an Ihren Schutzmaßnahmen werden.

Lektion 4 von 413 Schritte

Multi-Faktor-Authentifizierung und Kontowiederherstellung ist eine kostenlose Secure Coding & OWASP Top 10 for Backend-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Secure Coding & OWASP Top 10 for Backend-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Secure Coding & OWASP Top 10 for Backend-Kurs umfasst insgesamt 4 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

Beyond the Password

Strong access control and good session management still rest on one assumption: the user is who they claim. Passwords alone are weak. Multi-factor authentication adds layers so a stolen password is not enough.

The Three Factors

Authentication factors fall into categories:

  • Something you know — password, PIN
  • Something you have — phone, hardware key
  • Something you are — fingerprint, face

MFA combines two or more different categories.

TOTP Authenticator Apps

Time-based One-Time Passwords generate a 6-digit code from a shared secret and the current time. The server computes the same code to verify.

import pyotp
totp = pyotp.TOTP(user_secret)
is_valid = totp.verify(submitted_code)

Why SMS Is Weaker

SMS codes are better than nothing but vulnerable to SIM swapping and interception. Prefer TOTP apps or hardware keys; reserve SMS as a last-resort option.

Hardware Keys and WebAuthn

WebAuthn uses public-key cryptography with a hardware or platform authenticator. There is no shared secret to phish — the strongest widely available MFA.

Backup Codes

What if a user loses their phone? Issue one-time backup codes at enrollment. Store them hashed, just like passwords, and invalidate each after use.

stored = hash(backup_code)
# on use: verify then mark consumed

Recovery Is an Attack Surface

Account recovery often bypasses MFA. If recovery only needs an email link, an attacker who controls the inbox owns the account. Recovery must be as strong as login.

Secure Recovery Tokens

Recovery links should use a high-entropy, single-use, short-lived token, stored hashed and invalidated on use or password change.

token = secrets.token_urlsafe(32)
store(hash(token), expires_in=900)  # 15 minutes

Avoid Recovery Pitfalls

  • Do not reveal whether an email exists (enumeration)
  • Rate-limit recovery requests
  • Notify the user when recovery is initiated
  • Require re-enrollment of MFA after a full reset

Step-Up Authentication

For sensitive actions — changing email, large transfers — require a fresh factor even within an active session. This step-up limits the damage of a hijacked session.

Rate-Limiting the MFA Step

The MFA code entry is itself a target. A six-digit code has only a million possibilities, so without limits an attacker can brute-force it. Rate-limit and lock out after a few wrong codes, and expire each code quickly.

Quick Check

Test your MFA and recovery knowledge.

Recap

You strengthened authentication:

  • MFA combines factors from different categories
  • Prefer TOTP and WebAuthn over SMS
  • Provide hashed backup codes
  • Make recovery as strong as login with single-use, expiring tokens
  • Use step-up auth for sensitive actions
Kostenlos starten

Lerne Secure Coding & OWASP Top 10 for Backend mit einem KI-Tutor — kostenlos

Schreibe und führe echten Code in deinem Browser aus, bekomme sofortige Hilfe von einem 24/7 KI-Tutor und setze dein Lernen im Web oder in der App fort.

Kurse
12
Lektionen
48

Häufig gestellte Fragen

Ist die Lektion „Multi-Faktor-Authentifizierung und Kontowiederherstellung“ kostenlos?

Ja — der vollständige Text von „Multi-Faktor-Authentifizierung und Kontowiederherstellung“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Secure Coding & OWASP Top 10 for Backend-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Secure Coding & OWASP Top 10 for Backend-Kurs umfasst insgesamt 4 Lektionen.

Was lerne ich in „Multi-Faktor-Authentifizierung und Kontowiederherstellung“?

Stärken Sie die Authentifizierung mit MFA über Passwörter hinaus und entwerfen Sie sichere Abläufe zur Kontowiederherstellung, die nicht zu einer Hintertür an Ihren Schutzmaßnahmen werden. Du übst Secure Coding & OWASP Top 10 for Backend mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um Secure Coding & OWASP Top 10 for Backend zu starten?

Keine Vorkenntnisse erforderlich. Secure Coding & OWASP Top 10 for Backend auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.

Wie lange dauert die Lektion „Multi-Faktor-Authentifizierung und Kontowiederherstellung“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser Secure Coding & OWASP Top 10 for Backend-Lektion Code schreiben und ausführen?

Ja. Jede Secure Coding & OWASP Top 10 for Backend-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Starke Zugriffskontrolle implementieren
  2. Sichere Mechanismen zur Benutzerauthentifizierung
  3. Best Practices für Sitzungsverwaltung
  4. Multi-Faktor-Authentifizierung und Kontowiederherstellung
← Zurück zu Secure Coding & OWASP Top 10 for Backend