Skip to content

Conversation

clarfonthey
Copy link

Although Google has recommended 10 bytes, this may be prone to brute-force attacks and the RFC itself suggests 20 bytes. This simply changes the default secret size to match that.

I also made a PR to gitea (go-gitea/gitea#4287), where I increased the default to 40. That PR also contains more motivation.

@pquerna pquerna merged commit 7b7d3c7 into pquerna:master Jun 21, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants