Comment by elderlybanana
6 hours ago
Yes, TOTP is a secret + computation, and generating it is trivial once you have the secret. The security difference is that the TOTP secret is separate from the user’s password and the output is short-lived. Each of the two factors address different threat models.
No comments yet
Contribute on Hacker News ↗