2 ms·
I've yet to discover a 2FA implementation where the TOTP secret was human-sourced. A language without a secure RNG (e.g. PHP before 7.0, unless you have the ri
by CiPHPerCoder 8y ago
I've yet to discover a 2FA implementation where the TOTP secret was human-sourced.
A language without a secure RNG (e.g. PHP before 7.0, unless you have the right extensions enabled) might be a source of concern, but that's relatively rare.