Hacker News new | ask | show | jobs
Why you don't need to rush 2FA (getsentinel.io)
2 points by r4id4 1372 days ago
1 comments

TLDR of the article:

Usually, the last 2 expired tokens (-60 seconds) and the immediate next token (+30 seconds) other than the current one (+0 seconds) are accepted, but it’s up to the actual implementation.

Despite this, it's safe to say that you don’t have to rush it: even though 1 second is left you can safely copy/paste the token and it will likely be accepted!