Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, TOTP is a password. Hell, it is in the name. One property it has that differs from classic passwords is the authentication factor. For TOTP, it changes from something you know you something you have. However, lots of passwords are now randomly generated and are no longer "something you know" either.


> it is in the name

The "Password" named in "Time-based One Time Password" is the temporary generated value you transmit. It's not what's stored on the TOTP device, so in the context of this discussion, that temp value isn't what the gp was referring to.


> Yeah, TOTP is a password. Hell, it is in the name.

Careful; "one-time password" is in the name, and it certainly isn't that. Your TOTP seed stays valid forever.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: