4 ms·
so you're suggesting that someone is going to attempt to guess a 6 digit code? this is not offline brute-force, you're not going to iterate over thousands of c
by CyberRage 5y ago
so you're suggesting that someone is going to attempt to guess a 6 digit code?
this is not offline brute-force, you're not going to iterate over thousands of codes...
Passwords are permanent, that's the main difference. the code is only relevant to 30 secs after that it is useless. passwords are always useful because they never change.
Also people tend to re-use or slightly modify their password. with TOTP codes, the previous code doesn't tell you anything regarding the next code.
- toast0 5y ago> so you're suggesting that someone is going to attempt to guess a 6 digit code? Yeah, what else are you going to do when you get a 2fa prompt that you're not prepared to phish? It's unlikely to be right, and you only get a couple tries, but just because it's unlikely to be right doesn't mean it won't be sometimes. And you probably already blew your cover getting to the prompt, may as well make a go.