Comment by vel0city
1 month ago
In every system I've worked on recent successful TOTPs have been cached as well to validate they're not used more than once.
1 month ago
In every system I've worked on recent successful TOTPs have been cached as well to validate they're not used more than once.
In fact, re-reading RFC 6238 it states:
https://datatracker.ietf.org/doc/html/rfc6238
Assuming your adversary isn't actually directly impersonating you but simply gets the result from the successful attempt a few seconds later, the OTP should be invalid, being a one time password and all.