Comment on 6 digit OTP for Two Factor Auth (2FA) is brute-forceable in 3 daysparentComments−duskwuff4yNot practically. The standard requires that the secret contain at least 128 bits of randomness, and recommends more.
Comments
Not practically. The standard requires that the secret contain at least 128 bits of randomness, and recommends more.