Project

General

Profile

Feature #30

add option to configure hash type for CTP and SLP generation

Added by The 2nd almost 6 years ago. Updated almost 6 years ago.

Status:
Erledigt
Priority:
Normal
Assignee:
Target version:
Start date:
02 February 2015
Due date:
% Done:

0%


Description

this should improve protection against dictionary attacks if someone was able to keylogg/sniff both, the OTP and the CTP
  • we should split e.g. a 128 char hash into four 32 char strings and choose a random one for CTP/SLP creation
    • this should be configurable per client because some clients may not support any hash type (e.g. sha512)

Subtasks

Feature #37: implement support for different hash types for CTP generation in roundcube pluginNeuThe 2nd

History

#1 Updated by The 2nd almost 6 years ago

implemented for CTPs now. SLP is less important but may follow later...

#2 Updated by The 2nd almost 6 years ago

  • Status changed from Neu to Gelöst

#3 Updated by The 2nd almost 6 years ago

  • Status changed from Gelöst to Erledigt

Also available in: Atom PDF