Date: Fri, 29 Mar 2019 17:04:27 +0100 From: "e@...tmx.net" <e@...tmx.net> To: passwords@...ts.openwall.com Subject: Re: UX/security of TOTP configuration process On 03/29/19 17:03, Anton Dedov wrote: > Hello folks! > > A question on implementing TOTP 2FA in an application. > > Is it ok to ask users to backup TOTP secret in a secure place during 2fa > configuration process? Or it's better to provide one-time recovery codes? > > The argument against TOTP secret backup can be an assumption that if the > secret leak it can be maliciously used without victim user ever noticing it. if it could be used it is not ONE TIME then u r lying to yourself.
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.