4 ms·
You should become familiar with the Open Web Application Security Project https://www.owasp.org/ https://www.owasp.org/ , who are working on all kinds of best p
by derobert 14y ago
You should become familiar with the Open Web Application Security Project https://www.owasp.org/ https://www.owasp.org/ , who are working on all kinds of best practices for web apps.
OWASP has a draft on password storage https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet and also one on password complexity https://www.owasp.org/index.php/Password_length_%26_complexity https://www.owasp.org/index.php/Password_length_%26_complexi... .
They have plenty more, like guides on common security vulnerabilities, etc.