Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not sure what you are talking about TOTP suffering from a similar issue.

TOTP works via a secret key provided by the service. The TOTP(secret key + time) function generates a 6 digit code. This is a standard. The secret key can be stored on Authenticators and those authenticators sync to cloud services.

When adding the secret key for the first time to your authenticator, you have to also copy that to a notepad. This way if you want to transfer the keys, you have them available. Authenticator apps don't always allow you to export the keys. TOTP.app is a good auth app that does allow but there is no sync to cloud capability.



What I mean is that they don't say "Scan this QR code with your time-based one-time password (TOTP) app." They say "scan this QR code with your Google Authenticator app" or "scan this code with the HMRC app", obfuscating the fact that you can scan that code with any app that supports TOTP authentication like 1Password, Bitwarden, Authy etc. All of those prompts should have a link saying "Click here if you're not sure what TOTP apps are" that goes to a page with links to a whole bunch of recognised authenticator apps, where they can show their own if they want to but also show others that people may already use.


Ah yes! TOTP education takes much time. There are very few people who have invested time in teaching the uninformed about TOTP. OTOH, many more have invested time in developing TOTP apps and hacks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: