logoalt Hacker News

waterproofyesterday at 7:21 PM1 replyview on HN

The QR code that you use to transfer TOTP secrets to a new phone, is static. It never changes (unless you add a new service) and it requires no verification.

Do with that information what you will.


Replies

zamadatixyesterday at 7:25 PM

If you can have a copy or deployment of your TOTP code accessible (or memorized) at any time then you've solved the same problem already!