Comment on 6 digit OTP for Two Factor Auth (2FA) is brute-forceable in 3 daysparentComments−duskwuff4yWhat do you mean by that? The TOTP standard doesn't specify how (if at all) the client is secured. Besides, the one-time code is used in addition to a password, not as a substitute for one.
Comments
What do you mean by that? The TOTP standard doesn't specify how (if at all) the client is secured. Besides, the one-time code is used in addition to a password, not as a substitute for one.