Hacker News new | ask | show | jobs
by Ayesh 1369 days ago
All my TOTP prompts (on websites I run) account for such delays and clock skews by checking against the previous and next TOTP. So even if the user is a little bit late to enter the OTP, I can still validate it and complete authentication.
1 comments

This is standard practice with big corporate RSA remote login.