3 ms·
1. There is a window of tokens valid at any given time, its called: look-ahead synchronization window size (http://www.ietf.org/rfc/rfc4226.txt http://www.ietf
by danielpal 14y ago
1. There is a window of tokens valid at any given time, its called:
look-ahead synchronization window size (http://www.ietf.org/rfc/rfc4226.txt http://www.ietf.org/rfc/rfc4226.txt)
2. The synced time value should also be encrypted and authenticated.
No exactly what you are thinking. Time is transfered using https, so it's encrypted by that protocol, not our own.
3. Yes there is a slight delay, but see look-ahead synchronization window.
4. 2. If my phone doesn't have Internet connections, the code is only refreshed in ~5s.
No. The code is refreshed same way as if it had internet connection. It's just we used previous information on how your device clock works to make educated guesses on synchronization.
5. When the server wants to verify the received code it will check whether it matches with the codes generated in 0s, 5s, 10s, 15s and 20s.
Yeah something very similar to this.
Read the RFC, we follow it very closely:
http://www.ietf.org/rfc/rfc4226.txt http://www.ietf.org/rfc/rfc4226.txt
- zhuzhuor 14y agoThanks