Skip to content

Comment on 6 digit OTP for Two Factor Auth (2FA) is brute-forceable in 3 daysparent

Comments

There is a window of validity (often 30s), and a window of forgiveness (often +- 30s, so the same code will work for 90s), but the standards require only one attempt per window which renders TFA's claim pointless. Except for poor implementations, of course. And once in a million windows it may be 000000 (with 30s windows that will take 347 days assuming even distribution)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.