argon2id-owasp-2024-config-and-password-policy

OWASP 2024 argon2id production parameters: time=3, memory=64MB, parallelism=4. Pair with zxcvbn strength check (minimum score 3) and minimum 12-character length. Account lockout: 10 consecutive failures triggers 15-minute lockout. Rate-limit login endpoints at 5 requests/minute per IP via slowapi with Redis backing.