Hacker News new | ask | show | jobs
by jmprspret 697 days ago
> Attacker could do this as well,

No they cannot. They should not/will not be able to view that initial TOTP generation code. That is the "secret" that determines what digits are generated at one time.