In fairness this is more then rehashing NIST 800-63. This is coming from a Google engineer who worked on their authentication systems. A lot of good advice here, starting with not building your own.
> Google engineer
Oh, so basically scripture then.
Wait before you make rash judgments: he also worked on Bitcoin.
No, he worked on a Java SPV implementaton of Bitcoin.