View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 20366 | Bug reports | Security | public | 2025-11-21 12:28 | 2025-12-19 10:54 |
| Reporter | kemweb | Assigned To | DenisChenu | ||
| Priority | none | Severity | tweak | ||
| Status | in code review | Resolution | open | ||
| Summary | 20366: TwoFactorAdminLogin secret should have 128 bits | ||||
| Description | Common tools like FreeOTP consider less than 128 bits as unsafe. | ||||
| Tags | No tags attached. | ||||
| Bug heat | 254 | ||||
| Complete LimeSurvey version number (& build) | . | ||||
| I will donate to the project if issue is resolved | |||||
| Browser | |||||
| Database type & version | |||||
| Server OS (if known) | |||||
| Webserver software & version (if known) | |||||
| PHP Version | |||||
|
Decision needed
|
|
|
I would prefer (2) to add this as config option in the plugin with a default of 160 (as they have in RobThree/TwoFactorAuth). |
|
OK i take it. And maybe like that
Unless there is a possibility, however slim, that there is an advantage in bidding less than 128. |
|
|
I see no reason to use less then 128 bit. |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2025-11-21 12:28 | kemweb | New Issue | |
| 2025-11-21 18:00 | c_schmitz | Project | Feature requests => Bug reports |
| 2025-11-21 18:00 | c_schmitz | Severity | feature => tweak |
| 2025-11-21 18:00 | c_schmitz | Complete LimeSurvey version number (& build) | => . |
| 2025-12-02 19:14 | tibor.pacalat | Assigned To | => DenisChenu |
| 2025-12-02 19:14 | tibor.pacalat | Status | new => ready for code review |
| 2025-12-03 10:10 | DenisChenu | Status | ready for code review => in code review |
| 2025-12-03 10:10 | DenisChenu | Note Added: 83980 | |
| 2025-12-03 10:10 | DenisChenu | Bug heat | 250 => 252 |
| 2025-12-17 17:57 | DenisChenu | Assigned To | DenisChenu => tibor.pacalat |
| 2025-12-17 17:58 | DenisChenu | Note Added: 84033 | |
| 2025-12-19 10:13 | kemweb | Note Added: 84044 | |
| 2025-12-19 10:13 | kemweb | Bug heat | 252 => 254 |
| 2025-12-19 10:38 | DenisChenu | Note Added: 84045 | |
| 2025-12-19 10:38 | DenisChenu | Assigned To | tibor.pacalat => DenisChenu |
| 2025-12-19 10:54 | kemweb | Note Added: 84046 |