Want to go from zero working #infosec knowledge to a reasonable amount in the shortest time possible? Read NIST's "SP 800-63-3: Digital Identity Guidelines" for free at https://www.nist.gov/itl/tig/projects/special-publication-800-63
It's an excellent crash course on how to write a decently secure user login system. It's readable. It's largely counterintuitive. It explains *why* they recommend each specific piece of advice.
Also, when you see someone making a bad choice later, you have the authority to say "no, we shouldn't do this."