4 ms·
They give you a secret, in the form of a QR code (for smartphone users) or a text string. You put the secret string in a password manager that supports one tim
by johdo 4y ago
They give you a secret, in the form of a QR code (for smartphone users) or a text string.
You put the secret string in a password manager that supports one time code generation, like Gopass or KeepassXC.
When you login with your user name and password, the 2FA adds a second step where it asks for a "one time code", which your password manager provides. That code is temporary and only works for a short time frame.
In my case I use Gopass ( https://github.com/gopasspw/gopass https://github.com/gopasspw/gopass ) and it's as simple as adding a field like
---
totp: thesecretstringblahblah
at the end of my password entries and the app will treat that field as the source to generate one time codes. There's a browser addon and all I have to do is click the one time code and CTRL+V it into the field.
- eesmith 4y agoThank you for the details, and pointer to a solution. I've just installed gopass. I also (in looking through other threads) found https://github.com/gopasspw/gopass https://github.com/gopasspw/gopass and by reading the code learned how TOTP works.