The audit found that we weren't expiring idle sessions properly, which is a forward secrecy risk. We happened to implement proper expiry of idle sessions during the audit (a4c5b52 and e77c211), so in theory that finding is already remediated.
However, I'm filing this to go and re-check the detailed finding description against what we implemented, and verify that we didn't miss anything.
The audit found that we weren't expiring idle sessions properly, which is a forward secrecy risk. We happened to implement proper expiry of idle sessions during the audit (a4c5b52 and e77c211), so in theory that finding is already remediated.
However, I'm filing this to go and re-check the detailed finding description against what we implemented, and verify that we didn't miss anything.