HTTPS-only · PBKDF2-hashed passwords · 12 h session · HMAC-signed tokens