4 ms·
Well, the thirty second window in practice is usually a 2 - 3 minute window, as TOTP servers are set up to allow for drift, network issues, human slowness etc.
by robxorb 2y ago
Well, the thirty second window in practice is usually a 2 - 3 minute window, as TOTP servers are set up to allow for drift, network issues, human slowness etc. For sure, memorising more than a handful may be hard but it's just "11 Nov 14:35", etc.
I wonder if something could be set up to be both more secure, and more tailored to this use-case. Be pretty sweet to embed a 2FA in users brains somehow.
- 8organicbits 2y agoI think it would be easier to use HOTP for that as the codes are one time use and aren't time based. The user just needs to memorize one of the next N codes.
- masfuerte 2y agoIf you are able to choose the seed you could brute force it so that it produced a memorable code at a memorable time.
- robxorb 2y agoThat's a very cool idea, with the caveat that if an attacker knew you were doing that, the search space for your key would shrink.
- dotancohen 2y ago> Be pretty sweet to embed a 2FA in users brains somehow. 2FA already has a concept of "Something that you know". Still, "Something that you could calculate without revealing the thing that you know" is an interesting concept.
- refulgentis 2y agoThis is a fascinating idea. Would you mind if we call it a "cryptographic hash"?
- dotancohen 2y agoWell, it's been a long time since then, but I've had some crypto and some hash mess with my brain. ))