3 ms·
Would a fix to this be to make OTP’s 10 seconds rather than 30? Or is that not feasible/doesn’t make a difference?
by hoofedear 5y ago
Would a fix to this be to make OTP’s 10 seconds rather than 30? Or is that not feasible/doesn’t make a difference?
- lucb1e 5y agoJust run through the scenario you have in mind: would the attacker not be able to easily automate the forwarding of the OTP? Would grandmas still be able to use online banking? It's a trade-off, and validity periods so short that the user has to race a potential attacker, I don't think that's viable.