Hacker News new | ask | show | jobs
by trhaynes 1879 days ago
https://en.wikipedia.org/wiki/Time-based_One-Time_Password
1 comments

Doesn't that mean the client holds the keys/secret of some sort is shared with the client so it can either generate or verify?
you only need the pub key to verify