Hacker News new | ask | show | jobs
by pc86 793 days ago
I always forget which services this works for and which ones it doesn't :)
2 comments

This feature of TOTP auth is universal afaik.
If you set it up this way. An admin can choose not to or could allow e. g. 8 previous codes. That would allow four and a half minutes to put in any code of this timespan.
Nope. They need to implement it server-side.
There is some pretty surprising service that doesn't support this, the moment it disappears from your phone the code is no longer valid. It might be Microsoft if you're not using MS's auth app? Like I said I forget which one it is so I always just wait if I'm <5 seconds from expiry, but it is big enough that I was very surprised when it happened.
might as well try it while you're waiting, yeah? if you get in, you're done. if not, you were just going to wait anyways.