Hacker News new | ask | show | jobs
by somethingAlex 1507 days ago
That's pretty much what happened here. Obviously it's going to look a bit different afterwards because you have to mathematically tangle the time, key, and domain together. You can't really do that with the six digits of a traditional OTP code.

And like the other reply stated, if you can't mathematically tie them together, you have to rely on the user validating the domain (which you can't).