3 ms·
Both Authy and Google are based on open standards: Specifically: http://tools.ietf.org/html/rfc6238 http://tools.ietf.org/html/rfc6238 So you can add support
by danielpal 14y ago
Both Authy and Google are based on open standards:
Specifically: http://tools.ietf.org/html/rfc6238 http://tools.ietf.org/html/rfc6238
So you can add support as long as you support the standard.
When you scan the QR Code with you camera we read a secret key and store it inside your phone securely.
- scottmp10 14y agoOk that makes sense, thanks.
- dtjohnnymonkey 14y agoI'm reading RFC 6238 and it looks like it's based on a single shared secret: > Basically, the output of the HMAC-SHA-1 calculation is truncated to > obtain user-friendly values: > > HOTP(K,C) = Truncate(HMAC-SHA-1(K,C)) > > where Truncate represents the function that can convert an HMAC-SHA-1 > value into an HOTP value. K and C represent the shared secret and > counter value; Does that mean it's formally/theoretically equivalent to simply having two separate passwords?
- danielpal 14y agoAbsolutly not. It's one secret seed but you use the time to generate different One Time Passwords every 10 seconds, which means you never reuse passwords. This would be the equivalent of having 2 passwords, one of which you change every-time you use it and it's fully random.
- dtjohnnymonkey 14y agoSo just to rephrase it to make sure I understand, it's more secure because even if the OTP is compromised, the entire system is not compromised, is that correct? However, if the original secret is compromised (K), then could an attacker easily generate OTPs?
- X-Istence 14y agoYes. Just like with a physical RSA hardware token ...