5 ms·
> HOTP spec, however, does place a minimum requirement - but no maximum: >> Implementations MUST extract a 6-digit code at a minimum and possibly 7 and 8-digit
by echoangle 2y ago
> HOTP spec, however, does place a minimum requirement - but no maximum:
>> Implementations MUST extract a 6-digit code at a minimum and possibly 7 and 8-digit code. Depending on security requirements, Digit = 7 or more SHOULD be considered in order to extract a longer HOTP value. RFC 4226 - 5.3. Generating an HOTP Value
Am I bad at reading specs or is there a maximum here? If I say „minimum 6, possibly 7 or 8“, that sounds like 9 and more isn’t allowed.
- Jtsummers 2y agoHOTP requires a minimum of 6 digits (R4 in Section 4), but does not actually set a maximum. The algorithm in the RFC caps at 9-digits per Section E.2 (and my cursory reading of the code). That's not a required limit, but a technical limit of their choices. It also happens that 9-digits probably is about as big as you'd want to go, three 3-digit chunks aren't much harder to remember and type in correctly but past that it'd become increasingly impractical. The "and possibly 7 and 8-digit code" should be taken as descriptive, not prescriptive. The requirements occur earlier in the document and do not set a maximum. If they'd intended 8 as the maximum then they wouldn't have presented an algorithm that goes to 9 digits and would have stated it clearly in the requirements section, or followed up the HOTP RFC with another one clarifying these details. https://datatracker.ietf.org/doc/html/rfc4226 https://datatracker.ietf.org/doc/html/rfc4226