Increase the TOTP secret length > 128 bits (RFC requirements)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • martu
    Junior Member
    • Sep 2026
    • 2

    #1

    Increase the TOTP secret length > 128 bits (RFC requirements)

    Hi!

    I would like to propose improving the implementation of 2FA with TOTP: Would it be possible to implement an algorithm that uses a secret length of more than 128 bits?

    Currently, the secret length is 80 bits (16 characters x 5 bits), and this triggers a warning in authentication apps (FreeOTP warning: TOKEN IS UNSAFE! The token you are attempting to add contains weak cryptographic parameters. Use of this token is strongly discouraged! Please alert your token provider.)

    The RFC 4226 (https://datatracker.ietf.org/doc/html/rfc4226#autoid-4 ) states "The algorithm MUST use a strong shared secret. The length of the shared secret MUST be at least 128 bits. This document RECOMMENDs a shared secret length of 160 bits."

    Do you think this could be implemented in future releases? I don't know if it would involve a lot of work, but if it doesn't, I think it could really help improve the tool's security standards!

    Thank you very much for maintaining this powerful open-source tool!
    ​
  • yuri
    EspoCRM product developer
    • Mar 2014
    • 10064

    #2
    Hi,

    Done: https://github.com/espocrm/espocrm/c...09f066f883e9d8

    Comment

    • martu
      Junior Member
      • Sep 2026
      • 2

      #3
      Great! I'm very glad you were able to implement the suggested change! Thank you so much!

      Although, I've just updated to 10.0.9 and the TOTP secret is still 16 characters so 80 bits.

      Should I so something more?

      Click image for larger version

Name:	Screenshot 2026-10-01 at 12-08-02 Base de datos de Fembloc.png
Views:	8
Size:	54.2 KB
ID:	128115
      Click image for larger version

Name:	Screenshot 2026-10-01 at 12-07-10 Admine.png
Views:	7
Size:	77.2 KB
ID:	128116

      Comment

      • ThomasB
        Senior Member
        • Mar 2022
        • 204

        #4
        The change is not yet in the latest version. I guess it will be in a next major version.

        Comment

        • yuri
          EspoCRM product developer
          • Mar 2014
          • 10064

          #5
          Correct, except for 'major' version, as it will be in a minor release (the second part of the version number).

          Comment

          Working...