Authentication: How Can You Prove Who You Are?
Authentication is about providing evidence about who you are. When you need to register for a
library card, you may need to show your passport to prove that the name you register the card under
really belongs to you. With a website like p2p.wrox.com, you need to provide an e-mail address
and a password. Together, these two pieces form the evidence that proves your identity. Many other
mechanisms are used for authentication, including high-tech fi ngerprint or iris scans, smart cards
and tokens (where the evidence is stored on something tangible), and so on. However, in light of
the discussion on security of ASP.NET websites, this chapter sticks to a username and password for
authentication. In many cases, e-mail addresses act as usernames because they uniquely identity
a user.