7 ms·
The HOTP counter is something you can increment yourself if needed when storing it somewhere? Proper implementations of TOTP do not just rely on expiring the c
by Rafert 10y ago
The HOTP counter is something you can increment yourself if needed when storing it somewhere?
Proper implementations of TOTP do not just rely on expiring the codes. From chapter 5.2 of RFC 6238: "Note that a prover may send the same OTP inside a given time-step window multiple times to a verifier. The verifier MUST NOT accept the second attempt of the OTP after the successful validation has been issued for the first OTP, which ensures one-time only use of an OTP."
- vel0city 10y agoYep, right at the top of page 7 of the RFC: https://tools.ietf.org/html/rfc6238 https://tools.ietf.org/html/rfc6238 If it accepted the same token more than once, it couldn't possibly be called a "one-time password".