Hacker News new | ask | show | jobs
by zurn 3296 days ago
Smartphones are insecure unless you can control all your users have new Apple phones.

The problem with many affordable TOTP tokens is clock drift. Are RSA's tokens better with that?

1 comments

Was there a practical attack on TOTP on smartphones that affected 40M users and spilled industrial secrets? SecurID managed to hit both of these.