django-planet
May 11, 2019

6 digit OTP for Two Factor Auth (2FA) is brute-forceable in 3 days

published by Luke Plant
in blog Luke Plant
original entry 6 digit OTP for Two Factor Auth (2FA) is brute-forceable in 3 days

OTP/TOTP for two factor auth (2FA/MFA) is very easy to misunderstand and implement insecurely