2 ms·
Assuming the attacker has neither the password nor the OTP seed and must brute-force both (which is what 2FA is all about), the OTP doesn't add more security th
by CyberShadow 8y ago
Assuming the attacker has neither the password nor the OTP seed and must brute-force both (which is what 2FA is all about), the OTP doesn't add more security than the bits it has (about 20 for a 6-digit decimal number), plus the 1 bit because it's not constant. For this reason, I think it's misleading to say that there are moving goalposts or such. Neither the entire attack nor any part of it must be completed within 30 seconds or whatever the refresh interval is of the OTP token. Cracking both is still a classic brute-force attack.