|
|
|
|
|
by 8cvor6j844qw_d6
296 days ago
|
|
Symmetric as another poster mentioned. With some margin for connection delays (e.g., server checks 3 codes (1 forward and 1 backward) for a total of 90 seconds) [1]. I'll be interested in a asymmetric variant although I'll probably use a popular library and call it a day if I have to get involved in 2FA. [1]: https://auth0.com/blog/the-working-principles-of-2fa-2-facto... |
|
It’s been a while since I did any crypto. But it feels like the shortness of the one-time-code probably makes it impossible to do asymmetrically. If this is indeed the case there is probably an elegant proof or some better way of thinking about why it’s impossible. I would be interested in reading that.