From 1a7594be93a9a3904e4d0f9d5435f63f86c702f1 Mon Sep 17 00:00:00 2001 From: "R. Miles McCain" Date: Sun, 28 Jun 2020 17:55:59 +0000 Subject: [PATCH] Use SHA256 for more secure session association --- shynet/analytics/tasks.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/shynet/analytics/tasks.py b/shynet/analytics/tasks.py index 3c9732c..7b80762 100644 --- a/shynet/analytics/tasks.py +++ b/shynet/analytics/tasks.py @@ -1,7 +1,7 @@ import ipaddress import json import logging -from hashlib import sha1 +from hashlib import sha256 import geoip2.database import user_agents @@ -73,7 +73,7 @@ def ingress_request( if payload.get("loadTime", 1) <= 0: payload["loadTime"] = None - association_id_hash = sha1() + association_id_hash = sha256() association_id_hash.update(str(ip).encode("utf-8")) association_id_hash.update(str(user_agent).encode("utf-8")) session_cache_path = (