Hacker News new | ask | show | jobs
by duskwuff 1642 days ago
What do you mean by that? The TOTP standard doesn't specify how (if at all) the client is secured. Besides, the one-time code is used in addition to a password, not as a substitute for one.