<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=644" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2011-02-28T04:59:36+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=644</id>
<entry>
<author><name><![CDATA[captaincarrot]]></name></author>
<updated>2011-02-28T04:59:36+01:00</updated>
<published>2011-02-28T04:59:36+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=644&amp;p=2597#p2597</id>
<link href="https://forum.yubico.com/viewtopic.php?t=644&amp;p=2597#p2597"/>
<title type="html"><![CDATA[OATH-HOTP wrong key length]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=644&amp;p=2597#p2597"><![CDATA[
Hi there,<br /><br />According to the standards for HOTP the key should be a minimum of 128bits for best security, however the personalisation tool (windows) enforces a minimum of 160bits.<br /><br />I'm attempting to use a YubiKey to replace the Google Authenticator app and I notice that they use a key length of 80bits.<br /><br />Are we able to allow the personalisation program to use a variable key length instead of enforcing a 160bit key? That would allow me to use my YubiKey with Googles Existing Two-Factor Authentication system.<br /><br />You can take a look at the standard here: <br /><!-- m --><a class="postlink" href="http://www.ietf.org/rfc/rfc4226.txt">http://www.ietf.org/rfc/rfc4226.txt</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1558">captaincarrot</a> — Mon Feb 28, 2011 4:59 am</p><hr />
]]></content>
</entry>
</feed>