3 ms·
This only works for services using TOTP mode; HOTP prevents replay/cloning attacks.
by asuffield 10y ago
This only works for services using TOTP mode; HOTP prevents replay/cloning attacks.
- Rafert 10y agoThe HOTP counter is something you can increment yourself if needed when storing it somewhere? Proper implementations of TOTP do not just rely on expiring the codes. From chapter 5.2 of RFC 6238: "Note that a prover may send the same OTP inside a given time-step window multiple times to a verifier. The verifier MUST NOT accept the second attempt of the OTP after the successful validation has been issued for the first OTP, which ensures one-time only use of an OTP."
- vel0city 10y agoYep, right at the top of page 7 of the RFC: https://tools.ietf.org/html/rfc6238 https://tools.ietf.org/html/rfc6238 If it accepted the same token more than once, it couldn't possibly be called a "one-time password".