Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Increase default TOTP secret size to 20 bytes #30

Merged
merged 1 commit into from
Jun 21, 2018
Merged

Increase default TOTP secret size to 20 bytes #30

merged 1 commit into from
Jun 21, 2018

Conversation

clarfonthey
Copy link
Contributor

Although Google has recommended 10 bytes, this may be prone to brute-force attacks and the RFC itself suggests 20 bytes. This simply changes the default secret size to match that.

I also made a PR to gitea (go-gitea/gitea#4287), where I increased the default to 40. That PR also contains more motivation.

@pquerna pquerna merged commit 7b7d3c7 into pquerna:master Jun 21, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants