Skip to content

Comment on 6 digit OTP for Two Factor Auth (2FA) is brute-forceable in 3 days

Comments

I think what’s important here is when there can’t or won’t be a “lock out” after a certain number of tries. I’ve seen a few door locks based on TOTPish. They won’t lock you out because who knows why. You can just stick a device outside the door, slamming the BLE endpoint with codes until it unlocks, sorta like a proxmark used to do for keyless entries (maybe still does, haven’t messed with them since ‘08ish)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.