logoalt Hacker News

swiftcoderyesterday at 8:43 AM1 replyview on HN

Isn't this just manually hashing a password with a timed-salt? I don't see how this relates to TOTP


Replies

ulrikrasmussenyesterday at 8:46 AM

TOTP is also just hashing a password with a time salt. The purpose is just to prove that you are in possession of the device that stores the password without actually ever entering the password anywhere where it can be leaked. In this case the device is just your brain.

show 1 reply