You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jul 18, 2022. It is now read-only.
Hi @halllo,
Unfortunately, that's a bigger task than it sounds. We do have some changes planned for this (and the other) Web SDK clients, and we will definitely be using more modern crypto as part of that project.
In the meantime, our security teams are keeping a close eye on our use of HMACSHA1 and are, for the moment, satisfied with its security for this use case. If anything changes on that front, we will definitely prioritize a crypto update.
Duo strongly recommends migrating web applications to the new prompt experience. The new prompt uses the latest cryptography and hopefully addresses your concern about HMACSHA1.
Please consider upgrading to HMACSHA512 for the crypto.
The text was updated successfully, but these errors were encountered: