Hello, we’ve just been dinged on a pentest with you for insufficient entropy on the verification / recovery codes. Is it possible to configure them to be longer / use a different character set?
b
bland-eye-99092
11/06/2024, 7:56 AM
No, the length is not configurable.
The flows are resilient against brute forcing the code though, because we limit each flow's submissions to 6 in total, after which the flow becomes voided and can't be used anymore.