Sign-in
Email and password, done carefully.
The oldest way to sign in is still the one many of your users expect. Synq keeps it, and does the parts that are easy to get wrong.
Hashed with Argon2id
Passwords are stored as Argon2id hashes with OWASP’s recommended parameters, and rehashed on sign-in when the parameters change.
Checked against known breaches
A new password is refused when it appears in known breaches. Only the first five characters of its hash ever leave Synq. A brand can turn the check off.
Slowed down, then locked
Wrong guesses for one address are free three times, then wait longer each time, and the tenth locks the address for 15 minutes. Every refusal reads the same, whether or not the account exists.
Verification and resets
Addresses are verified by email, and a forgotten password is reset by email. A password sign-up can’t take over an account someone else proves the address of later.
Read next
Want it before it is finished?
Tell us what you are building and which sign-in your users need.