Hacker News new | ask | show | jobs
by DavidSJ 2113 days ago
If the server had a public key with which it could verify OTPs, then the small search space (only 1 million for 6-digit OTPs) means an attacker with that key could also produce one.