3 ms·
I suppose that could work, but one potential advantage of TOTP is that the secret/seed used to generate the 6 digit codes is never transmitted and not at risk o
by EB66 5y ago
I suppose that could work, but one potential advantage of TOTP is that the secret/seed used to generate the 6 digit codes is never transmitted and not at risk of being intercepted.
It's also probably more user-friendly to put a TOTP secret/seed on a device than it would be a client certificate. A certificate would probably be too big to easily scan with a QR code. QR codes can hold large amounts of data, but with more data the QR becomes larger and the detail becomes very fine. The camera needs to be very good, lighting needs to be very good, etc.
- e12e 5y agoNeither is the key for a ssl cert generated on the device? In fact, with qr enrollment the 2fa approach does transmit/expose the secret (probably over https, but still).
- EB66 5y agoTrue, you can't generate a QR code without transmitting the TOTP secret/seed in some fashion, but it's a one-time event that's typically done over HTTPS like you suggested.
- Johnny555 5y agoJust as with normal server side TLS, the client doesn't send its private key (and it's not known to anyone but the client), so intercepting the certificate doesn't do the attacker any good. But if communications intercept is possible, even with TOTP the attacker could intercept the TOTP token for that session and use it to log in himself.